Manuel Leduc
35 exploits
Active since Sep 2022
XWiki 12.6.6-13.10.10 - Authenticated Remote Code Execution via FlamingoThemesCode.WebHome Style Property
CVSS 9.9
XWiki 11.8-rc-1-14.4.7 - Authenticated Privilege Escalation via Mail.MailConfig Page
CVSS 9.9
XWiki Platform <14.4.8-15.0-rc-1 - Info Disclosure
CVSS 7.5
XWiki Platform 2.40m-2-14.4.8, 14.10.4, 15.0 - Remote Code Execution via Crafted URL Payload
CVSS 9.9
XWiki 7.3-milestone-1-14.4.8 - Unauthenticated Exposure of Obfuscated Passwords via REST Endpoint
CVSS 7.5
XWiki Platform 12.9-14.4.8 - Authenticated Eval Injection via First Name Field
CVSS 9.9
XWiki 5.4.4-14.4.7 - Stored Cross-Site Scripting via AppWithinMinutes.FormFieldCategoryClass Page Title
CVSS 9.0
XWiki Platform 14.6-14.10.5 & CKEditor 1.9-1.64.8 - Authenticated XSS via CKEditor Config
CVSS 9.0
XWiki 2.5-14.4.8 - Authenticated Remote Code Execution via Script Macro Injection in Invitation.WebHome
CVSS 9.9
XWiki Platform <14.10.9, <15.3-rc-1 - Info Disclosure
CVSS 4.3