Sebastian Stehle
5 exploits
Active since Feb 2023
Squidex has SSRF via Backup Restore Endpoint — Admin-Controlled URL Download Allows Internal and External Requests
SSRF via Jint Scripting Engine HTTP Functions Due to Missing SSRF Protection on "Jint" HttpClient
Squidex vulnerable to Server-Side Request Forgery (SSRF) via URL-based asset upload (/api/apps/{app}/assets)
Squidex has Blind SSRF via file:// Protocol in Restore API leading to Local File Interaction
CVSS 5.5
squidex/squidex <7.4.0 - Info Disclosure
CVSS 6.1