Oliver Günther
4 exploits
Active since Jul 2017
OpenProject has Cross-Project Meeting Agenda Item Injection via Unscoped Section Lookup
CVSS 6.5
OpenProject <6.1.6 & <7.0.3 - Info Disclosure
CVSS 8.1
OpenProject < 16.6.2 - Authenticated Exposure of Sensitive User Information via Sequential User ID Enumeration
CVSS 3.5
OpenProject < 16.6.2 - Unauthenticated Brute-Force Attack via Password Change Endpoint
CVSS 6.5