Patrick Cloke
7 exploits
Active since Feb 2021
Sydent < 2.3.0 - Unauthenticated Denial of Service via Unbounded HTTP Request/Response
CVSS 7.5
Synapse < 1.25.0 - Server-Side Request Forgery via Third-Party Invite Events and Push Notifications
CVSS 3.1
Synapse 0.99.0-1.24.9 - Denial of Service via .well-known File Redirection
CVSS 4.3
Synapse < 1.27.0 - Cross-Site Scripting via Password Reset Endpoint
CVSS 6.9
Synapse < 1.27.0 - HTML Injection in Notification Emails
CVSS 6.1
Sydent < 2.3.0 - Unauthenticated Denial of Service via Unbounded HTTP Request/Response
CVSS 7.5
Synapse <1.95.1-1.96.0rc1 - Info Disclosure
CVSS 5.3