VYPR
Vendor

Tindy2013

Products
1
CVEs
2
Across products
2
Status
Private

Products

1

Recent CVEs

2
  • CVE-2020-35579HigDec 20, 2020
    risk 0.49cvss 7.5epss 0.01

    tindy2013 subconverter 0.6.4 has a /sub?target=%TARGET%&url=%URL%&config=%CONFIG% API endpoint that accepts an arbitrary %URL% value and launches a GET request for it, but does not consider that the external request target may indirectly redirect back to this original /sub…

  • CVE-2022-28927CriMay 19, 2022
    risk 0.03cvss 9.8epss 0.34

    A remote code execution (RCE) vulnerability in Subconverter v0.7.2 allows attackers to execute arbitrary code via crafted config and url parameters.