Loading HuntDB...

Concrete CMS - HackerOne Reports

View on HackerOne
42
Total Reports
1
Critical
6
High
11
Medium
15
Low
Weakness: Cross-site Scripting (XSS) - Stored

Stored XSS on Add Calendar

Reported by: gamliel | Disclosed:
Low
Weakness: Cross-site Scripting (XSS) - Stored
Weakness: Cross-site Scripting (XSS) - Stored
Weakness: Path Traversal
Weakness: Violation of Secure Design Principles
Weakness: Cross-site Scripting (XSS) - Stored
Weakness: Cross-site Scripting (XSS) - Stored
Weakness: Violation of Secure Design Principles

SSRF bypass

Reported by: pabl00nicarres | Disclosed:
Low
Weakness: Server-Side Request Forgery (SSRF)
Weakness: Cross-site Scripting (XSS) - Reflected
Weakness: SQL Injection
Weakness: Cross-site Scripting (XSS) - Reflected
Weakness: Cross-site Scripting (XSS) - Stored
Low
Weakness: Cross-site Scripting (XSS) - Stored
Weakness: Cross-site Scripting (XSS) - Stored
Weakness: Cross-site Scripting (XSS) - Stored
Weakness: Server-Side Request Forgery (SSRF)
Previous Page 2 of 3 Next