Simone Quatrini

7 exploits Active since Jun 2019
CVE-2019-9879 EXPLOITDB CRITICAL python WORKING POC
WPGraphQL 0.2.3 - RCE
The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registrations are allowed. This is related to the registerUser mutation.
CVSS 9.8
CVE-2019-9880 EXPLOITDB CRITICAL python WORKING POC
WPGraphQL <0.2.3 - Info Disclosure
An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible, for an unauthenticated attacker, to retrieve all WordPress users details such as email address, role, and username.
CVSS 9.1
CVE-2019-9879 WRITEUP CRITICAL WORKING POC
WPGraphQL 0.2.3 - RCE
The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registrations are allowed. This is related to the registerUser mutation.
CVSS 9.8
CVE-2019-9880 WRITEUP CRITICAL WORKING POC
WPGraphQL <0.2.3 - Info Disclosure
An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible, for an unauthenticated attacker, to retrieve all WordPress users details such as email address, role, and username.
CVSS 9.1
CVE-2021-33506 WRITEUP HIGH WRITEUP
Jitsi Meet <2.0.5963-1 - Privilege Escalation
jitsi-meet-prosody in Jitsi Meet before 2.0.5963-1 does not ensure that restrict_room_creation is set by default. This can allow an attacker to circumvent conference moderation.
CVSS 7.5
CVE-2019-9881 EXPLOITDB MEDIUM python WORKING POC
WPGraphQL 0.2.3 - XSS
The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on any article, even when 'allow comment' is disabled.
CVSS 5.3
EIP-2026-104201 EXPLOITDB python WORKING POC
Citadel WebCit < 926 - Session Hijacking Exploit