About

Hi, my name is Stefan Schiller (@scryh_). I have been a computer enthusiasts since my early childhood. Nowadays my main focus of interest is security research.

Discovered Vulnerabilities

Here is a list of vulnerabilities I discovered in public software:

SoftwareVulnerabilityImpactCVEReference
OverleafArgument InjectionLoad Arbitrary Dictionary FileCVE-2024-45312GitHub
OverleafInsecure Default SettingRCECVE-2024-45313GitHub
OpenAPI GeneratorUnvalidated User InputArbitrary File Read / DeleteCVE-2024-35219GitHub
Wyze Cam v3Command InjectionAssisted RCECVE-2024-6247ZDI-24-838
JoomlaSanitizer Bypass (Cross-Site Scripting)Assisted RCECVE-2024-21726Blog
Firefly IIICross-Site ScriptingLimited by CSPCVE-2024-22075Blog
Apache Allura (SourceForge)Logical (Arbitrary File Read)RCECVE-2023-46851Blog
SquidexCross-Site ScriptingAssisted RCECVE-2023-46252Blog
SquidexPath TraversalRCECVE-2023-46253Blog
JetBrains TeamCityAuthentication BypassRCECVE-2023-42793Blog
DOMSanitizerSanitizer Bypass (Cross-Site Scripting)App SpecificCVE-2023-49146Commit
Apache GuacamoleUse-After-FreeRCECVE-2023-30576Patch Notes
Apache GuacamoleGuacamole Protocol InjectionInformation Disclosure, File ReadCVE-2023-30575Patch Notes
Apache OpenMeetingsNull-Byte InjectionRCECVE-2023-29246Patch Notes
Apache OpenMeetingsLogicalAuth BypassCVE-2023-29032Patch Notes
Apache OpenMeetingsWeak Hash ComparisonAuth BypassCVE-2023-28936Patch Notes
OpenRefineZip SlipAssisted RCECVE-2023-37476GitHub
NETGEAR RAX30Stack-based Buffer OverflowRCECVE-2023-34285ZDI-23-839
PretalxPath TraversalLimited File WriteCVE-2023-28458Blog
PretalxPath TraversalArbitrary File ReadCVE-2023-28459Blog
NetdataCommand InjectionRCECVE-2023-22496GitHub
NetdataLogicalAuth BypassCVE-2023-22497GitHub
OpenNMSUnauthenticated, Stored XSSAssisted RCECVE-2023-0846GitHub
LibreNMSUnauthenticated, Stored XSSAssisted RCEBlog, huntr.dev
CactiLogical, Command InjectionRCECVE-2022-46169Blog, GitHub
NagVisType JugglingAuth BypassCVE-2022-3979Blog
NagVisArbitrary File ReadRCE chainCVE-2022-46945Blog
CheckmkCode InjectionRCE chainCVE-2022-46836Blog, Patch Notes
CheckmkLine Feed InjectionRCE chainCVE-2022-47909Blog, Patch Notes
CheckmkServer-Side Request ForgeryRCE chainCVE-2022-48321Blog, Patch Notes
Open Web AnalyticsInformation Disclosure / Arbitrary File WriteRCECVE-2022-24637Blog
mpv media playerFormat String / Heap OverflowAssisted RCECVE-2021-30145Blog
TeamSpeak 3Double-FreeDoSPatch Notes
AnyDeskFormat StringRCECVE-2020-13160Blog