Samuel Georges
14 exploits
Active since Sep 2015
OctoberCMS < 1.0.426 - Stored Cross-Site Scripting via SVG Avatar Upload
CVSS 5.4
OctoberCMS < 1.0.427 - Cross-Site Request Forgery via _handler Postback Variable
CVSS 8.8
user_project/user and rainlab/user-plugin < 1.5.0 - Stored Cross-Site Scripting in Name Field
CVSS 6.1
October CMS 1.0.471 - Unauthenticated Authentication Bypass via Crafted Request
CVSS 7.4
October CMS < 1.1.5 and System < 1.0.472 - Authentication Bypass via Password Reset
CVSS 8.2
October CMS < 1.0.319 - Stored Cross-Site Scripting via Profile Image Caption
October CMS build 271 and earlier - Cross-Site Scripting via File Title
CVSS 5.4
October CMS <1.0.469 - Code Injection
CVSS 5.2
October CMS 1.0.471 - Unauthenticated Authentication Bypass via Crafted Request
CVSS 7.4
October CMS < 1.1.5 and System < 1.0.472 - Authentication Bypass via Password Reset
CVSS 8.2
October CMS < 1.0.473 and 1.1.0-1.1.6 - Authenticated Remote Code Execution via Twig Template Injection
CVSS 8.8
October CMS < 1.0.473 and 1.1.0-1.1.6 - Authenticated Remote Code Execution via Theme Import Feature
CVSS 8.8
October < 1.0.471 - Insufficient Session Expiration via Session Reactivation
CVSS 9.8
OctoberCMS < 1.0.474 - Authenticated Remote Code Execution via Safe Mode Bypass
CVSS 7.2