Patrick Hener
8 exploits
Active since Jul 2020
Kardex Control Center - Code Injection
CVSS 9.8
Inneo Startup Tools < 13.0.70.3804 - Path Traversal
CVSS 9.8
goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS
CVSS 6.5
goshs is Missing Write Protection for Parametric Data Values
CVSS 7.7
goshs has a file-based ACL authorization bypass in goshs state-changing routes
CVSS 9.8
goshs has Auth Bypass via Share Token
CVSS 8.1
Kardex Control Center - Code Injection
CVSS 9.8
Inneo Startup Tools < 13.0.70.3804 - Path Traversal
CVSS 9.8