Tín Phạm (aka TF1T)
14 exploits
Active since Oct 2023
mojoportal 2.7.0.0 - Remote Code Execution via File Manager Upload
CVSS 9.8
mojoportal 2.7.0.0 - Remote Code Execution via Skin Management File Upload
CVSS 9.8
mojoportal 2.7.0.0 - Remote Code Execution via Skin Management Layout.master File
CVSS 9.8
mojoportal 2.7.0.0 - Cross-Site Scripting via Help.aspx helpkey Parameter
CVSS 6.1
Frappe ERPNext 15.57.5 - SQL Injection via txt Parameter in get_material_requests_based_on_supplier()
CVSS 8.2
Frappe ERPNext 15.57.5 - SQL Injection via blanket_order_type Parameter
CVSS 8.2
Frappe ERPNext 15.57.5 - SQL Injection via inventory_dimensions_dict Parameter
CVSS 8.2
Frappe ERPNext 15.57.5 - SQL Injection via txt Parameter in get_rfq_containing_supplier()
CVSS 8.2
Frappe ERPNext v15.57.5 - SQL Injection via import_coa() company parameter
CVSS 6.5
Frappe ERPNext 15.57.5 - SQL Injection via get_stock_balance() inventory_dimensions_dict Parameter
CVSS 7.5
Frappe ErpNext v15.57.5 - SQL Injection via filters.disabled Parameter
CVSS 6.5
Frappe 14.0.0-14.96.10 - SQL Injection via dt Parameter in add_tag()
CVSS 6.5
Frappe ErpNext v15.57.5 - SQL Injection via timelog Parameter in get_timesheet_detail_rate()
CVSS 6.5
Frappe ERPNext 15.57.5 - SQL Injection via Loyalty Program Expiry Date Parameter
CVSS 6.5