Skip to content
View cassis-sec's full-sized avatar
💜
Make SSRF Great Again
💜
Make SSRF Great Again
Block or Report

Block or report cassis-sec

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
cassis-sec/README.md

cassis@pwnbox:~$ whoami

  • I am 22 years old and live in Rome
  • Cyber Security Analyst & Security Researcher

Full Metal Alchemist

⚡Technologies

Parrot Splunk Cynet Redmine DarkTrace

📰 Public CVE

Date CVE ID Description
11/04/2023 CVE-2023-26847 A stored Cross-Site Scripting (XSS) vulnerability in OpenCATS v0.9.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the state parameter at opencats/index.php?m=candidates.
11/04/2023 CVE-2023-26846 A stored Cross-Site Scripting (XSS) vulnerability in OpenCATS v0.9.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the city parameter at opencats/index.php?m=candidates.
11/04/2023 CVE-2023-26845 A Cross-Site Request Forgery (CSRF) in OpenCATS 0.9.7 allows attackers to force users into submitting web requests via unspecified vectors.

🌐 Social

LinkedIn Twitter GitHub TryHackMe HackTheBox

🥅 GitHub Goals

Quickdraw

Stats

📫 Contacts

ProtonMail OpenPGP

Pinned

  1. CVE CVE Public

    List of vulnerabilities that I discovered.

    1