Thomas Mortagne
52 exploits
Active since Feb 2022
XWiki Platform: Path traversal via resources parameter in ssx and jsx endpoints when using leading slash
XWiki Platform REST /wikis/{wikiName} - Unauthenticated XAR Import
XWiki Platform < 12.10.6 - Missing Authorization via Page Template Copy
CVSS 6.5
XWiki Platform <3.0-milestone-1 - Privilege Escalation
CVSS 5.4
XWiki < 14.0 - Uncontrolled Resource Consumption via Large Object Addition
CVSS 5.7
XWiki Platform <3.0-milestone-1 - Privilege Escalation
CVSS 5.4
XWiki < 14.0 - Uncontrolled Resource Consumption via Large Object Addition
CVSS 5.7
XWiki < 14.4.8, 12.6.1-13.10.11, 14.6-rc-1-14.10.3 - Code Injection via LegacyNotificationAdministration since Parameter
CVSS 9.9
XWiki 3.3-14.10.6 - Incorrect Authorization via Velocity Script Execution
CVSS 9.1
XWiki Platform - SQL Injection
CVSS 9.8
XWiki <14.10.22, <15.10.12, <16.4.3, <16.7.0 - Info Disclosure
CVSS 5.3
XWiki Platform - SQL Injection
CVSS 9.8
XWiki Platform 4.3-milestone-1-16.10.8, 17.0.0-rc-1-17.4.1 - SQL Injection via REST Search orderField Parameter
XWiki < 16.10.6 - SQL Injection via Hibernate Query Sanitization Bypass
CVSS 9.8
XWiki <16.10.11, 17.4.4, 17.7.0 - Info Disclosure
CVSS 7.5
XWiki Blog Application < 9.15.7 - Stored Cross-Site Scripting via Blog Post Title
CVSS 9.0
XWiki Platform < 13.0 - Incorrect Authorization via Document Save with Elevated Rights
CVSS 5.4
XWiki Platform < 12.10.6 - Missing Authorization via Page Template Copy
CVSS 6.5
XWiki < 13.6 - Path Traversal via SSX Document Reference Export
CVSS 6.8
XWiki < 12.10.9, 13.4.3, >=13.6-rc-1 <13.7-rc-1 - Arbitrary File Read via XWiki#invokeServletAndReturnAsString
CVSS 5.5
XWiki Commons 2.7-12.10.9, 13.0-13.4.3, 13.5-13.7.9 - XML External Entity Injection via XML Script Service
CVSS 4.9
XWiki Platform Flamingo Theme UI <12.10.11,14.0-rc-1,13.4.7,13.10.3...
CVSS 7.4
XWiki Platform Wiki UI Main Wiki <5.3-milestone-2 - XSS
CVSS 7.4
XWiki Platform <12.10.3,14.0 - Path Traversal
CVSS 2.7
XWiki Platform <12.10.11-14.0-rc-1-13.4.7-13.10.3 - XSS
CVSS 7.4