alaeddine03
14 exploits
Active since Jun 2023
TinaCMS CLI <2.1.8 - Path Traversal
CVSS 8.4
ssw/tinacms/cli < 2.1.8 - Unauthenticated Arbitrary File Read via Vite Dev Server Misconfiguration
CVSS 6.2
ssw/tinacms/cli < 2.1.8 - Unauthenticated Path Traversal and Arbitrary File Write via CORS Misconfiguration
CVSS 9.6
Pydio Cells < 3.0.12 - Unauthenticated Privilege Escalation via External User Role Assignment
CVSS 8.8
rallly < 4.5.4 - Authenticated Authorization Bypass via Comment Deletion API
CVSS 7.1
rallly < 4.5.4 - Authenticated User Impersonation via Comment AuthorName Field
CVSS 6.5
rallly < 4.5.4 - Authenticated Insecure Direct Object Reference via ParticipantId Parameter
CVSS 6.5
rallly < 4.5.4 - Authenticated Insecure Direct Object Reference via Poll Duplication Endpoint
CVSS 6.5
rallly < 4.5.4 - Authenticated Authorization Bypass via PollId Parameter
CVSS 8.1
rallly < 4.5.6 - Unauthenticated Information Disclosure via API Endpoint
CVSS 6.5
rallly < 4.5.4 - Authenticated Authorization Bypass in Poll Management
CVSS 8.1
rallly < 4.5.4 - Authenticated Insecure Direct Object Reference via Poll Finalization
CVSS 9.1
rallly < 4.5.4 - Authenticated Insecure Direct Object Reference via ParticipantId Parameter
CVSS 6.5
rallly < 4.5.4 - Authenticated Insecure Direct Object Reference in Participant Deletion Endpoint
CVSS 8.1