martinfrancois

2 exploits Active since Jun 2018
CVE-2021-36460 NOMISEC HIGH WRITEUP
VeryFitPro 3.2.8 - Privilege Escalation
VeryFitPro (com.veryfit2hr.second) 3.2.8 hashes the account's password locally on the device and uses the hash to authenticate in all communication with the backend API, including login, registration and changing of passwords. This allows an attacker in possession of a hash to takeover a user's account, rendering the benefits of storing hashed passwords in the database useless.
CVSS 7.8
CVE-2018-1000529 NOMISEC MEDIUM WORKING POC
Grails Fields plugin < 2.2.8 - Cross-Site Scripting via Display Tag
Grails Fields plugin version 2.2.7 contains a Cross Site Scripting (XSS) vulnerability in Using the display tag that can result in XSS . This vulnerability appears to have been fixed in 2.2.8.
CVSS 6.1