Chad Wilson
11 exploits
Active since Apr 2022
GoCD 17.5.0-22.1.0 - LDAP Injection via Username Parameter
CVSS 8.2
GoCD < 23.1.0 - Stored Cross-Site Scripting via Pipeline Label Configuration
CVSS 5.4
GoCD < 22.1.0 - Authenticated Remote Code Execution via Mercurial Hook Branch Name Injection
CVSS 8.8
GoCD <22.2.0 - Privilege Escalation
CVSS 5.0
GoCD < 23.1.0 - Stored Cross-Site Scripting via Pipeline Label Configuration
CVSS 5.4
GoCD 20.5.0-23.1.0 - Database Credential Exposure via Backup Failure Alert
CVSS 4.2
GoCD 19.4.0-23.5.0 - Reflected Cross-Site Scripting via Redirect Query Parameter
CVSS 3.1
GoCD < 24.5.0 - Authenticated Privilege Escalation via Configuration XML UI
CVSS 8.8
GoCD 18.9.0-24.4.0 - Authenticated Arbitrary Script Execution via Backup Configuration Post-Backup Script
CVSS 3.8
GoCD 16.7.0-24.4.0 - Authenticated XML External Entity Injection via Configuration Repository
CVSS 7.2
GoCD < 24.5.0 - Authenticated XML External Entity Injection via Group Admin Raw XML Configuration
CVSS 7.1