Manuel
78 exploits
Active since Sep 2021
Parse Server: LiveQuery subscription query depth bypass
CVSS 7.5
Parse Server: Session update endpoint allows overwriting server-generated session fields
CVSS 4.3
Parse Server: Denial of service via unindexed database query for unconfigured auth providers
CVSS 7.5
Parse Server: SQL injection via aggregate and distinct field names in PostgreSQL adapter
CVSS 7.2
Parse Server: MFA recovery code single-use bypass via concurrent requests
CVSS 2.7
Parse Server: Auth data exposed via /users/me endpoint
CVSS 6.5
Parse Server: MFA single-use token bypass via concurrent authData login requests
CVSS 4.4
Parse Server: LiveQuery protected field leak via shared mutable state across concurrent subscribers
CVSS 5.3
Parse Server: GraphQL API endpoint ignores CORS origin restriction
CVSS 8.8
Parse Server: Cloud function validator bypass via prototype chain traversal
CVSS 9.1
Parse Server: GraphQL complexity validator exponential fragment traversal DoS
CVSS 7.5
Parse Server: Session field immutability bypass via falsy-value guard
CVSS 5.4
Parse Server: LiveQuery protected-field guard bypass via array-like logical operator value
CVSS 4.3
Parse Server: Auth data exposed via verify password endpoint
CVSS 6.5
Parse Server: Streaming file download bypasses afterFind file trigger authorization
CVSS 7.5
Parse Server: Auth data exposed via verify password endpoint
CVSS 6.5
Parse Server: Streaming file download bypasses afterFind file trigger authorization
CVSS 7.5
Parse Server: MFA single-use token bypass via concurrent authData login requests
CVSS 4.4
Parse Server: LiveQuery protected field leak via shared mutable state across concurrent subscribers
CVSS 5.3
Parse Server: GraphQL API endpoint ignores CORS origin restriction
CVSS 8.8
Parse Server: Cloud function validator bypass via prototype chain traversal
CVSS 9.1
Parse Server: GraphQL complexity validator exponential fragment traversal DoS
CVSS 7.5
Parse Server: Session field immutability bypass via falsy-value guard
CVSS 5.4
Parse Server: LiveQuery protected-field guard bypass via array-like logical operator value
CVSS 4.3
Parse Server: Email verification resend page leaks user existence
CVSS 5.3