Vincent Massol
6 exploits
Active since Mar 2023
Server-Side Request Forgery (SSRF) in PlantUML Macro via 'server' parameter
CVSS 4.4
XWiki JIRA Extension 4.2-8.5.6 - Authenticated XML External Entity Injection via JIRA Macro
CVSS 7.7
XWiki 6.3-13.10.10 - Authenticated Remote Code Execution via UIX Parameter Injection
CVSS 9.9
XWiki Platform < 13.10.11 - XML External Entity Injection via XAR Import
CVSS 7.7
XWiki JIRA Extension 4.2-8.5.6 - Authenticated XML External Entity Injection via JIRA Macro
CVSS 7.7
XWiki 8.2-8.9 - Stored Cross-Site Scripting via Markdown HTML Import
CVSS 9.0