Rijk van Zanten
11 exploits
Active since Jan 2022
Directus < 10.13.3 - Improper Access Control via Loopback Device Bypass
CVSS 5.0
Directus < 10.13.3 - Improper Access Control via Loopback Device Bypass
CVSS 5.0
Directus < 10.13.3 - Unauthenticated Credential Exposure via OpenID/OAuth2 Redirect Cache
CVSS 7.4
Directus < 10.13.3 - Improper Access Control via Loopback Device Bypass
CVSS 5.0
Directus 9.0.0-alpha.4-9.4.1 - Stored Cross-Site Scripting via SVG File Upload
CVSS 5.4
Directus 9.0.0-alpha.4-9.4.1 - Stored Cross-Site Scripting via HTML File Upload
CVSS 5.4
Directus 9.0.0-beta.2-9.6.0 - Server-Side Request Forgery via Media Upload Functionality
CVSS 5.0
Directus 10.4.0-10.6.1 - Denial of Service via Invalid WebSocket Frame
CVSS 5.9
Directus < 10.13.0 - User Enumeration via SSO Error Messages
CVSS 7.5
Directus < 10.13.3 - Unauthenticated Credential Exposure via OpenID/OAuth2 Redirect Cache
CVSS 7.4
Directus < 10.13.2 - Sensitive Information Exposure in Log Files via Query String Access Token
CVSS 4.2