Roman Donchenko
12 exploits
Active since Jun 2024
CVAT: Stored XSS via annotation guides
CVAT 2.1.0-2.14.3 - Server-Side Request Forgery via Cloud Storage Endpoint URL
CVSS 7.1
CVAT 2.2.0-2.14.3 - Cross-Site Request Forgery via Dataset Export or Backup
CVSS 7.1
Computer Vision Annotation Tool 2.3.0-2.17.9 - Missing Authorization for Webhook Delivery Information
CVSS 6.4
CVAT 2.4.7-2.18.9 - Cross-Site Scripting via Malicious Task URL
CVSS 6.1
CVAT 2.16.0-2.18.9 - Cross-Site Request Forgery via Malicious URL
CVSS 6.1
CVAT 1.1.0-2.25.9 - Authenticated Remote Code Execution via Unsafe State Deserialization in Tracker Functions
CVSS 9.8
CVAT 2.4.0-2.38.0 - Authenticated Information Disclosure and Denial of Service
CVSS 4.3
CVAT 2.4.0-2.48.1 - Authenticated Path Traversal and Arbitrary File Write via File Share Mount
CVAT 2.8.1-2.52.0 - Authenticated Directory Listing via Path Traversal
CVSS 4.3
CVAT 2.2.0-2.54.0 - Stored Cross-Site Scripting via Malicious Label or SVG Upload
CVSS 5.4
CVAT <2.54.0 - Privilege Escalation
CVSS 8.8