Loading HuntDB...

Concrete CMS - HackerOne Reports

View on HackerOne
42
Total Reports
1
Critical
6
High
11
Medium
15
Low

SSRF thru File Replace

Reported by: zuh4n | Disclosed:
Weakness: Server-Side Request Forgery (SSRF)
Weakness: Deserialization of Untrusted Data
Weakness: Code Injection
Weakness: Cross-site Scripting (XSS) - Stored
Weakness: Server-Side Request Forgery (SSRF)
Weakness: Cross-site Scripting (XSS) - Stored
Weakness: Violation of Secure Design Principles
Weakness: Cross-Site Request Forgery (CSRF)
Weakness: Privilege Escalation
Weakness: Cross-site Scripting (XSS) - Generic
Weakness: Privilege Escalation
Weakness: Cross-site Scripting (XSS) - Stored
Weakness: Insecure Direct Object Reference (IDOR)
Weakness: Code Injection
Weakness: Cross-site Scripting (XSS) - Stored
Weakness: Cross-site Scripting (XSS) - Stored
Weakness: Open Redirect
Page 1 of 3 Next