vabene1111
9 exploits
Active since Jun 2022
Tandoor Recipes <2.5.1 - Path Traversal
CVSS 4.9
Tandoor Recipes < 2.5.1 - Authenticated Blind Server-Side Request Forgery via Cookmate Recipe Import
CVSS 7.7
Tandoor Recipes 0.9.1-1.2.5 - Server-Side Request Forgery via Import Recipe Functionality
CVSS 6.5
Tandoor Recipes 1.0.5-1.2.5 - Stored Cross-Site Scripting via Food Name Parameter
Tandoor Recipes 1.0.5-1.2.5 - Stored Cross-Site Scripting via Food Name Parameter in Copy to Clipboard
Tandoor Recipes 0.17.0-1.2.5 - Stored Cross-Site Scripting in Keyword/Food/Unit Name Field
Tandoor Recipes < 1.5.24 - Authenticated Server-Side Template Injection via Jinja2
CVSS 9.9
Tandoor Recipes < 1.5.28 - Unauthenticated Sensitive Information Exposure via External Storage Feature
CVSS 7.7
Tandoor Recipes < 1.5.28 - Unrestricted Upload of Dangerous File Types
CVSS 8.7