sysentr0py
10 exploits
Active since Jul 2024
Outline <= 0.76.1 - Session Fixation via Crafted Magic Sign-In Link
CVSS 8.8
Outline <= 0.76.1 - Open Redirect via State Cookie Manipulation
CVSS 6.1
LimeSurvey <= 6.5.12 - Cross-Site Request Forgery via GET Request
CVSS 8.8
Lime Survey <6.5.12 - Code Injection
CVSS 4.8
LimeSurvey < 6.6.2 - Remote Code Execution via js_localize.php lng Parameter Injection
CVSS 8.8
LimeSurvey <6.6.1+240806 - Host Header Injection
CVSS 6.5
syspass 3.2.0-3.2.10 - Cross-Site Scripting via Client Name Parameter
CVSS 6.1
SysPass 3.2.0-3.2.10 - Stored Cross-Site Scripting via Notification Type or Component
CVSS 5.4
SysPass 3.2.0-3.2.10 - Host Header Injection
CVSS 8.1
syspass 3.2.0-3.2.10 - Source Code Disclosure via Account File Upload Filename Mismanagement
CVSS 6.5