alacerda (velocista)

2 exploits Active since Apr 2021
CVE-2021-30144 WRITEUP MEDIUM WORKING POC
GLPI Dashboard <1.0.2 - Auth Bypass
The Dashboard plugin through 1.0.2 for GLPI allows remote low-privileged users to bypass access control on viewing information about the last ten events, the connected users, and the users in the tech category. For example, plugins/dashboard/front/main2.php can be used.
CVSS 4.3
CVE-2021-3486 WRITEUP MEDIUM WORKING POC
GLPi 9.5.4 - Stored Cross-Site Scripting via Metadata Injection
GLPi 9.5.4 does not sanitize the metadata. This way its possible to insert XSS into plugins to execute JavaScript code.
CVSS 6.1