Mitsuhiro Shibuya
7 exploits
Active since Nov 2023
CarrierWave has a denylisted_content_type bypass via Unescaped Regex Metacharacters
CVSS 4.7
CarrierWave has a denylisted_content_type bypass via Unescaped Regex Metacharacters
CVSS 4.7
CarrierWave < 2.2.5, >=3.0.0 <3.0.5 - Cross-Site Scripting via Content-Type Allowlist Bypass
CVSS 6.8
rails_admin < 2.3.0 and >=3.0.0.beta <3.1.3 - Cross-Site Scripting via List View HTML Title Attribute
CVSS 5.4
CarrierWave < 2.2.5, >=3.0.0 <3.0.5 - Cross-Site Scripting via Content-Type Allowlist Bypass
CVSS 6.8
CarrierWave < 2.2.6 and 3.0.0-3.0.7 - Cross-Site Scripting via Content-Type Header Bypass
CVSS 6.8
rails_admin < 2.3.0 and >=3.0.0.beta <3.1.3 - Cross-Site Scripting via List View HTML Title Attribute
CVSS 5.4