ImpressCMS - HackerOne Reports
View on HackerOne11
Total Reports
2
Critical
2
High
4
Medium
3
Low
Slack server disclose h1 private issue report
Reported by:
ex1st3nc3_
|
Disclosed:
Low
Weakness: Authentication Bypass Using an Alternate Path or Channel
Incorrect Authorization Checks in /include/findusers.php
Reported by:
egix
|
Disclosed:
Medium
Weakness: Incorrect Authorization
Arbitrary File Deletion via Path Traversal in image-edit.php
Reported by:
egix
|
Disclosed:
Medium
Weakness: Path Traversal
SQL Injection in version 1.4.3 and below
Reported by:
cyberinsane
|
Disclosed:
High
Weakness: SQL Injection
Download full backup and Cross site scripting
Reported by:
kurdishhacked
|
Disclosed:
High
Weakness: Cross-site Scripting (XSS) - Reflected
Stored XSS on 1.4.0
Reported by:
tehwinsam
|
Disclosed:
Medium
Weakness: Cross-site Scripting (XSS) - Stored
CVEs:
CVE-2020-17551
SQL injection when configuring a database
Reported by:
solov9ev
|
Disclosed:
Low
Weakness: SQL Injection
Other misconfiguration on Slack Server
Reported by:
ex1st3nc3_
|
Disclosed:
Critical
Weakness: Authentication Bypass Using an Alternate Path or Channel
Potential Authentication Bypass through "autologin" feature
Reported by:
egix
|
Disclosed:
Low
SQL Injection through /include/findusers.php
Reported by:
egix
|
Disclosed:
Critical
Weakness: SQL Injection
CSRF to XSS in /htdocs/modules/system/admin.php
Reported by:
d3addog
|
Disclosed:
Medium
Weakness: Cross-Site Request Forgery (CSRF)