Michael Howitz
6 exploits
Active since May 2021
Zope < 4.8.10 - Stored Cross-Site Scripting via SVG Image Upload
CVSS 3.7
Plone < 4.3.20 - Path Traversal
CVSS 6.8
RestrictedPython < 5.4 - Information Disclosure via Format String Injection
CVSS 8.3
AccessControl < 4.4 - Exposure of Sensitive Information via str.format_map
CVSS 6.8
Zope < 4.8.10 - Stored Cross-Site Scripting via SVG Image Upload
CVSS 3.7
CPython <3.13.2, RestrictedPython <8.0 - RCE
CVSS 7.9