Nicolas CARPi
4 exploits
Active since Jun 2021
elabftw allows MFA bypass during login
CVSS 5.9
elabftw < 4.0.0 - Blind Server-Side Request Forgery
CVSS 6.8
elabftw < 4.1.0 - Brute-Force Protection Bypass via PHPSESSID Manipulation
CVSS 5.9
elabftw < 5.3.0 - Stored Cross-Site Scripting via SVG File Upload
CVSS 6.8