Thomas Mortagne
52 exploits
Active since Feb 2022
XWiki Platform <13.10.6 & <14.30-rc-1 - XSS
CVSS 8.9
XWiki Platform Index UI < 13.10.6 - Stored Cross-Site Scripting via Deleted Attachments Index
CVSS 8.9
XWiki OIDC < 1.29.1 - Authentication Bypass via OpenID Provider Parameter Injection
CVSS 9.1
XWiki < 13.10.8 - Unauthenticated Arbitrary Page Modification via XAR Package Import
CVSS 9.6
XWiki Platform <3.0-milestone-1 - Privilege Escalation
CVSS 5.4
XWiki < 14.0 - Uncontrolled Resource Consumption via Large Object Addition
CVSS 5.7
XWiki 11.6-13.10.9 - Authenticated Privilege Escalation via Async Macro
CVSS 9.9
XWiki 6.2.1-13.10.9 - Unauthenticated Remote Code Execution via Icon Theme Sheet Injection
CVSS 9.9
XWiki Platform <2.3-milestone-1 - RCE
CVSS 9.9
XWiki < 14.4.8, 12.6.1-13.10.11, 14.6-rc-1-14.10.3 - Code Injection via LegacyNotificationAdministration since Parameter
CVSS 9.9
XWiki 3.3-milestone-2-14.10.3 - Incorrect Authorization
CVSS 9.9
XWiki Platform <2.2-14.4.8, <14.10.4, <15.0-rc-1 - XSS
CVSS 9.0
XWiki 8.1-14.10.5 - Incorrect Authorization via Tip UI Extension
CVSS 9.9
XWiki < 14.10.7 - Authenticated Cross-Site Request Forgery via Crafted URL
CVSS 9.6
XWiki 1.0-14.10.5 and 15.0-15.1 - Authenticated Remote Code Execution via Crafted Edit URL
CVSS 9.9
XWiki 3.3-14.10.6 - Incorrect Authorization via Velocity Script Execution
CVSS 9.1
XWiki 8.3-14.10.6 - Unauthenticated Velocity Script Execution via Document Tree
CVSS 8.3
XWiki < 15.10.16 - SQL Injection via Oracle DBMS_XMLGEN Function
CVSS 9.8
XWiki REST API Query - SQL Injection
CVSS 9.8
XWiki <14.10.22, <15.10.12, <16.4.3, <16.7.0 - Info Disclosure
CVSS 5.3
XWiki <15.10.14, <16.4.6, <16.10.0-rc-1 - Privilege Escalation
CVSS 9.8
XWiki OIDC 2.17.1-2.18.1 - Improper Authorization via User Profile Token Creation
XWiki Platform 4.3-milestone-1-16.10.8, 17.0.0-rc-1-17.4.1 - SQL Injection via REST Search orderField Parameter
XWiki < 16.10.6 - SQL Injection via Hibernate Query Sanitization Bypass
CVSS 9.8
XWiki Platform <16.10.6 - Info Disclosure
CVSS 9.1