Manuel
72 exploits
Active since Sep 2021
Parse Server: MFA single-use token bypass via concurrent authData login requests
CVSS 4.4
Parse Server: LiveQuery protected field leak via shared mutable state across concurrent subscribers
CVSS 5.3
Parse Server: GraphQL API endpoint ignores CORS origin restriction
CVSS 8.8
Parse Server: Cloud function validator bypass via prototype chain traversal
CVSS 9.1
Parse Server: GraphQL complexity validator exponential fragment traversal DoS
CVSS 7.5
Parse Server: Session field immutability bypass via falsy-value guard
CVSS 5.4
Parse Server: LiveQuery protected-field guard bypass via array-like logical operator value
CVSS 4.3
Parse Server: Auth data exposed via verify password endpoint
CVSS 6.5
Parse Server: Streaming file download bypasses afterFind file trigger authorization
CVSS 7.5
Parse Server: Auth data exposed via verify password endpoint
CVSS 6.5
Parse Server: Streaming file download bypasses afterFind file trigger authorization
CVSS 7.5
Parse Server: MFA single-use token bypass via concurrent authData login requests
CVSS 4.4
Parse Server: LiveQuery protected field leak via shared mutable state across concurrent subscribers
CVSS 5.3
Parse Server: GraphQL API endpoint ignores CORS origin restriction
CVSS 8.8
Parse Server: Cloud function validator bypass via prototype chain traversal
CVSS 9.1
Parse Server: GraphQL complexity validator exponential fragment traversal DoS
CVSS 7.5
Parse Server: Session field immutability bypass via falsy-value guard
CVSS 5.4
Parse Server: LiveQuery protected-field guard bypass via array-like logical operator value
CVSS 4.3
Parse Server: Email verification resend page leaks user existence
CVSS 5.3
Parse Server: Auth provider validation bypass on login via partial authData
CVSS 9.1
Parse Server: LiveQuery bypasses CLP pointer permission enforcement
CVSS 6.5
Parse Server: Protected field change detection oracle via LiveQuery watch parameter
CVSS 5.3
Parse Server: Query condition depth bypass via pre-validation transform pipeline
CVSS 7.5
Parse Server: LiveQuery subscription query depth bypass
CVSS 7.5
Parse Server: Session update endpoint allows overwriting server-generated session fields
CVSS 4.3