About Me

Table of Contents

Hi there! πŸ‘‹ I’m Javier Olmedo, a Cybersecurity Professional and CTF Player based in Toledo, Spain.

With over 8 years of professional experience, I specialize in Offensive Security, Web Exploitation, and Red Teaming. This blog is my personal knowledge base where I document my research, CVE discoveries, and capture-the-flag methodologies.

πŸ† Certifications

OSCP OSWE OSEP CRTO ICSI CNSS

πŸŽ–οΈ Badges & Achievements

MITRE ResDev MITRE LatMov Offshore Pro Lab

πŸ› Disclosed CVEs

I have discovered and reported vulnerabilities in various software. Below is a list of my assigned CVEs.

CVE IDVulnerability NameCVSS3CVSS2Exploit
CVE-2018-13832All In One Favicon <= 4.6 - Stored XSS4.8 🟠3.5 πŸŸ’βœ…
CVE-2018-14430Multi Step Form <= 1.2.5 - Reflected XSS6.1 🟠4.3 🟠❌
CVE-2018-15571Export Users to CSV <= 1.1.1 - CSV Injection8.6 πŸ”΄6.8 πŸŸ βœ…
CVE-2018-15873Sentrifugo HRMS 3.2 - Blind SQLi9.8 🟣7.5 πŸ”΄βœ…
CVE-2018-15917Jorani LMS 0.6.5 - Persistent XSS5.4 🟠3.5 πŸŸ’βœ…
CVE-2018-15918Jorani LMS 0.6.5 - SQL Injection5.4 🟠5.5 πŸŸ βœ…
CVE-2018-18478Libre NMS 1.43 - Stored XSS6.1 🟠4.3 🟠❌
CVE-2018-18921PHP Server Monitor 3.3.1 - CSRF6.5 🟠5.8 πŸŸ βœ…
CVE-2018-18922Ticketly 1.0 - Privilege Escalation9.8 🟣5.0 πŸŸ βœ…
CVE-2018-18923Ticketly 1.0 - Multiple SQLi9.8 🟣7.5 πŸ”΄βœ…
CVE-2018-19828Integria IMS 5.0.83 - Reflected XSS6.1 🟠4.3 πŸŸ βœ…
CVE-2018-19829Integria IMS 5.0.83 - CSRF6.5 🟠5.8 πŸŸ βœ…
CVE-2019-7400Rukovoditel ERP & CRM 2.4.1 - Reflected XSS6.1 🟠4.3 πŸŸ βœ…
CVE-2019-15092WP Plugin Import Export Users 1.3.1 - CSV Injection7.3 πŸ”΄6.0 πŸŸ βœ…
CVE-2019-19031Easy XML Editor <= 1.7.8 - XXE8.1 πŸ”΄5.5 πŸŸ βœ…
CVE-2019-19032XMLBlueprint <= 16.191112 - XXE8.1 πŸ”΄5.5 πŸŸ βœ…
CVE-2020-9038Joplin <= 1.0.184 - File Read via XSS5.4 🟠3.5 🟒❌
CVE-2021-43091YesWiki - SQL Injection7.5 πŸ”΄5.0 🟠❌