Pascal Jufer
6 exploits
Active since Mar 2023
Directus <9.23.0 - Server-Side Request Forgery via File Import DNS Rebinding
CVSS 5.0
Directus < 10.10.0 - Open Redirect via Auth API Redirect Parameter
CVSS 5.4
Directus < 10.11.0 - Exposure of Sensitive Information via Alias Parameter
CVSS 4.9
Directus < 10.11.0 - Insufficient Session Expiration via JWT Token
CVSS 5.4
Directus < 10.11.2 - Denial of Service via Random String Generation Utility
CVSS 7.5
Directus < 10.12.0 - Denial of Service via GraphQL Field Duplication
CVSS 6.5