Lauri Ojansivu
32 exploits
Active since May 2023
WeKan < 8.19 - Authorization Bypass via Checklist Creation IDOR
CVSS 7.5
WeKan < 8.19 - Insecure Direct Object Reference via Checklist Card-Board Relationship Tampering
CVSS 7.5
WeKan < 8.19 - Incorrect Authorization in Card Update API
CVSS 6.5
WeKan < 8.19 - Incorrect Authorization in Card Move Logic
CVSS 5.4
WeKan < 8.19 - Authenticated Comment Author Spoofing via authorId Parameter
CVSS 4.3
WeKan < 8.19 - Incorrect Authorization via allowPrivateOnly Setting Bypass
CVSS 4.3
Wekan < 8.20 - Incorrect Authorization in Migration Functionality
CVSS 8.8