Sobre Mí

Table of Contents

¡Hola! 👋 Soy Javier Olmedo, profesional de la Ciberseguridad y jugador de CTFs con base en Toledo, España.

Con más de 8 años de experiencia profesional, me especializo en Seguridad Ofensiva, Explotación Web y Red Teaming. Este blog es mi base de conocimientos personal donde documento mis investigaciones, descubrimientos de CVEs y metodologías de capture-the-flag.

🏆 Certificaciones

OSCP OSWE OSEP CRTO ICSI CNSS

🎖️ Badges & Logros

MITRE ResDev MITRE LatMov Offshore Pro Lab

🐛 Historial de CVEs

He descubierto y reportado vulnerabilidades en diversos software. A continuación se muestra la lista de mis CVEs asignados.

ID CVEVulnerabilidadCVSS3CVSS2Exploit
CVE-2018-13832All In One Favicon <= 4.6 - Stored XSS4.8 🟠3.5 🟢
CVE-2018-14430Multi Step Form <= 1.2.5 - Reflected XSS6.1 🟠4.3 🟠
CVE-2018-15571Export Users to CSV <= 1.1.1 - CSV Injection8.6 🔴6.8 🟠
CVE-2018-15873Sentrifugo HRMS 3.2 - Blind SQLi9.8 🟣7.5 🔴
CVE-2018-15917Jorani LMS 0.6.5 - Persistent XSS5.4 🟠3.5 🟢
CVE-2018-15918Jorani LMS 0.6.5 - SQL Injection5.4 🟠5.5 🟠
CVE-2018-18478Libre NMS 1.43 - Stored XSS6.1 🟠4.3 🟠
CVE-2018-18921PHP Server Monitor 3.3.1 - CSRF6.5 🟠5.8 🟠
CVE-2018-18922Ticketly 1.0 - Privilege Escalation9.8 🟣5.0 🟠
CVE-2018-18923Ticketly 1.0 - Multiple SQLi9.8 🟣7.5 🔴
CVE-2018-19828Integria IMS 5.0.83 - Reflected XSS6.1 🟠4.3 🟠
CVE-2018-19829Integria IMS 5.0.83 - CSRF6.5 🟠5.8 🟠
CVE-2019-7400Rukovoditel ERP & CRM 2.4.1 - Reflected XSS6.1 🟠4.3 🟠
CVE-2019-15092WP Plugin Import Export Users 1.3.1 - CSV Injection7.3 🔴6.0 🟠
CVE-2019-19031Easy XML Editor <= 1.7.8 - XXE8.1 🔴5.5 🟠
CVE-2019-19032XMLBlueprint <= 16.191112 - XXE8.1 🔴5.5 🟠
CVE-2020-9038Joplin <= 1.0.184 - File Read via XSS5.4 🟠3.5 🟢
CVE-2021-43091YesWiki - SQL Injection7.5 🔴5.0 🟠