Natalie Tay
12 exploits
Active since Dec 2021
Discourse < 3.0.1 - Uncontrolled Resource Consumption via Membership Request Reason
CVSS 3.5
Discourse < 3.2.5 - Denial of Service via Long Tag Group Name
CVSS 4.9
Discourse < 3.2.5 - Unauthenticated iframe Injection via Allowed Iframes Bypass
CVSS 6.1
Discourse: Authorization bypass in oneboxer via user-controlled category id
CVSS 4.3
Discourse Poll Plugin post_id - Authorization Bypass
CVSS 5.3
Discourse < 2.7.11 - Unauthorized Exposure of Sensitive Tag Notifications
CVSS 4.3
Discourse < 3.0.0 - Denial of Service via Unlimited Chat Draft Length
CVSS 4.3
discourse/microsoft_authentication < 2024-02-20 - Incorrect Authorization via Microsoft Account Type Misconfiguration
CVSS 9.0
Discourse Calendar <0.4 - Info Disclosure
CVSS 4.3
Discourse Calendar < 2024-02-21 - Incorrect Authorization via Attendance Update Request
CVSS 6.5
Discourse < 3.2.5 - Denial of Service via Long Tag Group Name
CVSS 4.9
Discourse < 3.2.5 - Unauthenticated iframe Injection via Allowed Iframes Bypass
CVSS 6.1