Francesco Emanuel Bennici

2 exploits Active since Aug 2019
CVE-2019-15053 NOMISEC MEDIUM WORKING POC
Atlassian Html Include And Replace Macro < 1.4.2 - XSS
The "HTML Include and replace macro" plugin before 1.5.0 for Confluence Server allows a bypass of the includeScripts=false XSS protection mechanism via vectors involving an IFRAME element.
CVSS 6.8
CVE-2019-15233 NOMISEC MEDIUM WORKING POC
Oldstreetsolutions Live Input Macros < 2.11 - XSS
The Live:Text Box macro in the Old Street Live Input Macros app before 2.11 for Confluence has XSS, leading to theft of the Administrator Session Cookie.
CVSS 6.1