William Tantiono

2 exploits Active since Feb 2025
CVE-2024-57177 WRITEUP HIGH WRITEUP
perfood/couch-auth <= 0.21.2 - SSRF
A host header injection vulnerability exists in the NPM package of perfood/couch-auth <= 0.21.2. By sending a specially crafted host header in the email change confirmation request, it is possible to trigger a SSTI which can be leveraged to run limited commands or leak server-side information
CVSS 7.3
CVE-2024-57178 WRITEUP MEDIUM WRITEUP
Stock-Forecaster <=01-04-2020 - SQL Injection
An SQL injection vulnerability exists in Stock-Forecaster <=01-04-2020. By sending a specially crafted 'stock-symbol' parameter to the portofolio() endpoint, it is possible to trigger an SQL injection in the application. As a result, the attacker will be able the user data or manipulate the software behavior.
CVSS 5.9