Sylvain Jermini

6 exploits Active since Jan 2023
CVE-2023-0301 WRITEUP MEDIUM WRITEUP
GitHub alfio-event/alf.io <2.0-M4-2301 - XSS
Cross-site Scripting (XSS) - Stored in GitHub repository alfio-event/alf.io prior to Alf.io 2.0-M4-2301.
CVSS 5.4
CVE-2023-2258 WRITEUP HIGH WRITEUP
GitHub alfio-event/alf.io <2.0-M4-2304 - Info Disclosure
Improper Neutralization of Formula Elements in a CSV File in GitHub repository alfio-event/alf.io prior to 2.0-M4-2304.
CVSS 8.8
CVE-2023-2259 WRITEUP HIGH WRITEUP
GitHub alfio-event/alf.io <2.0-M4-2304 - Info Disclosure
Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository alfio-event/alf.io prior to 2.0-M4-2304.
CVSS 7.2
CVE-2023-2260 WRITEUP HIGH WRITEUP
Alf < 2.0-m4-2304 - IDOR
Authorization Bypass Through User-Controlled Key in GitHub repository alfio-event/alf.io prior to 2.0-M4-2304.
CVSS 8.8
CVE-2024-45299 WRITEUP MEDIUM WRITEUP
alf.io <2.0-M5 - XSS
alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5, the preloaded data as json is not escaped correctly, the administrator / event admin could break their own install by inserting non correctly escaped text. The Content-Security-Policy directive blocks any potential script execution. The administrator or event administrator can override the texts for customization purpose. The texts are not properly escaped. Version 2.0-M5 fixes this issue.
CVSS 6.5
CVE-2024-45300 WRITEUP HIGH WRITEUP
alf.io <2.0-M5 - Auth Bypass
alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5, a race condition allows the user to bypass the limit on the number of promo codes and use the discount coupon multiple times. In "alf.io", an event organizer can apply price discounts by using promo codes to your events. The organizer can limit the number of promo codes that will be used for this, but the time-gap between checking the number of codes and restricting the use of the codes allows a threat actor to bypass the promo code limit. Version 2.0-M5 fixes this issue.
CVSS 7.5