Stefan Nica
6 exploits
Active since Apr 2024
zenml < 0.56.2 - Authenticated Missing Authorization via API PUT /api/v1/users/id Endpoint
CVSS 6.5
zenml < 0.55.5 - Path Traversal via /api/v1/steps Logs URI Parameter
CVSS 9.9
zenml-io/zenml <0.55.4 - Auth Bypass
CVSS 3.3
zenml <= 0.55.5 - Clickjacking via Missing X-Frame-Options Header
CVSS 6.1
zenml < 0.57.0rc2 - Account Takeover via Unlimited Password Change Attempts
CVSS 5.4
ZenML 0.83.1 - Path Traversal and Arbitrary File Write via PathMaterializer
CVSS 7.8