Oliver Hader
38 exploits
Active since Jul 2020
TYPO3 CMS - Broken Access Control in Form Framework
TYPO3 CMS - Broken Access Control in Form Framework
TYPO3 CMS - Cross-Site Scripting in Indexed Search
TYPO3 CMS - Broken Access Control in Backend API
TYPO3 CMS - Broken Access Control in File Abstraction Layer
TYPO3 CMS - Insecure Deserialization in Core API
TYPO3 CMS - Broken Access Control in Form Framework
TYPO3 CMS - Broken Access Control in Form Framework
TYPO3 CMS - Cross-Site Scripting in Indexed Search
TYPO3 CMS - Broken Access Control in Backend API
TYPO3 CMS - Broken Access Control in File Abstraction Layer
TYPO3 CMS - Insecure Deserialization in Core API
TYPO3 CMS - Privilege Escalation & SQL Injection in Form Framework
TYPO3 HTML Sanitizer allows Cross-Site Scripting
TYPO3 8.7.0-8.7.50, 10.0.0-10.4.34, 11.0.0-11.5.22, 12.0.0-12.1.9 - Persisted XSS via PATH_INFO Injection
CVSS 8.8
TYPO3 html_sanitizer < 1.5.3 - Cross-Site Scripting via DOM Processing Instruction Bypass
CVSS 4.7
TYPO3 <9.0.0-<9.5.48 ELTS,<10.4.45 ELTS,<11.5.37 LTS,<12.4.15 LTS,<...
CVSS 5.4
TYPO3 <9.0.0-<9.5.48 ELTS,<10.4.45 ELTS,<11.5.37 LTS,<12.4.15 LTS,<...
CVSS 5.4
TYPO3 10.0.0-10.4.47 - Cross-Site Request Forgery via Backend Deep Links
CVSS 4.3
TYPO3 10.0.0-10.4.47 - Cross-Site Request Forgery via Backend Deep Links
CVSS 4.3
TYPO3 10.0.0-10.4.47 - Cross-Site Request Forgery via Backend Deep Links
CVSS 4.3
TYPO3 10.0.0-10.4.47 - Cross-Site Request Forgery via Backend Deep Links
CVSS 4.3
TYPO3 CMS Stores Cleartext Password in User Settings Module
CVSS 7.5
mediace 7.6.2-7.6.4 - Authenticated Remote Code Execution via Checksum Verification Bypass
CVSS 9.8
TYPO3 CMS >=9.0.0 <9.5.20, >=10.0.0 <10.4.6 - RCE
CVSS 8.8