Sami Mazouz
7 exploits
Active since Jan 2021
Flarum Sticky 0.1.0-beta.14-0.1.0-beta.15 - XSS
CVSS 5.4
Flarum 1.5.0-1.6.1 - Stored Cross-Site Scripting via Discussion Title Input
CVSS 9.0
Flarum < 1.6.3 - Unauthenticated Information Disclosure via Mentions Feature
CVSS 7.7
Flarum < 1.6.3 - Missing Authorization in Notification-Sending Component
CVSS 6.8
Flarum 1.3.0-1.6.2 - Missing Authorization for Discussion Replies via REST API
CVSS 3.5
flarum < 1.7.0 - Authenticated Path Traversal via LESS Parser
CVSS 6.6
Flarum < 1.8.0 - Authenticated Server-Side Request Forgery via File Upload MIME Spoofing
CVSS 7.1