Natalie Tay
9 exploits
Active since Dec 2021
Discourse: Authorization bypass in oneboxer via user-controlled category id
CVSS 4.3
Discourse has a poll authorization bypass via post_id array parameter
CVSS 5.3
Discourse - Info Disclosure
CVSS 4.3
Discourse < 3.0.0 - Resource Allocation Without Limits
CVSS 4.3
Discourse <patched - Auth Bypass
CVSS 9.0
Discourse Calendar <0.4 - Info Disclosure
CVSS 4.3
Discourse Calendar < 2024-02-21 - Incorrect Authorization
CVSS 6.5
Discourse < 3.2.5 - Denial of Service
CVSS 4.9
Discourse < 3.2.5 - Injection
CVSS 6.1