Articles by Mathieu Farrell

13 articles
Date Tue 25 June 2024
Author Mathieu Farrell
Category Pentest

Discovery of two vulnerabilities (CVE-2024-34065) in Strapi, an open source content management system. In this post we explain how these vulnerabilities, if chained together, allow authentication to be bypassed.

Date Thu 21 March 2024
Author Mathieu Farrell
Category Pentest

The following article explains how during a Red Team engagement we were able to develop a 1day for GLPI CVE-2023-43813 which later led to the identification of an arbitrary object instantiation leading to an SSRF referenced as CVE-2024-27098 as well as an SQL injection referenced as CVE-2024-27096.

Date Tue 13 February 2024
Author Mathieu Farrell
Category Pentest

Discovery of a new gadget chain in Laravel.