OsamaSayegh
9 exploits
Active since Sep 2022
Discourse <2.8.14 - stable & <3.0.0.beta16 - beta & tests-passed - ...
CVSS 5.7
Discourse < 3.0.1 and < 3.1.0.beta2 - Cross-Site Scripting via User Full Name Field
CVSS 4.4
Discourse beta and tests-passed < 3.1.0.beta7 - Unauthenticated Cross-Site Scripting via CSP Nonce Reuse
CVSS 6.8
Discourse <3.2.3-3.3.0.beta4-dev - Privilege Escalation
CVSS 4.9
Discourse <2.8.9-2.9.0.beta10 - RCE
CVSS 9.1
Discourse <2.8.14 - stable & <3.0.0.beta16 - beta & tests-passed - ...
CVSS 5.7
Discourse < 3.0.1 and < 3.1.0.beta2 - Cross-Site Scripting via User Full Name Field
CVSS 4.4
Discourse <3.2.3-3.3.0.beta4-dev - Privilege Escalation
CVSS 4.9
Discourse < 3.3.3 and < 3.4.0 - Authenticated Denial of Service via Inline Onebox URL Endpoint
CVSS 4.3