Page MenuHomeVulnz
Feed All Stories

Mar 17 2019

avm99963 changed the visibility for T9: Access to transcripts for other UB students.
Mar 17 2019, 11:33 PM · Unknown Object (Project)
avm99963 changed the status of T9: Access to transcripts for other UB students from Fixed to Verified.

I received a repsonse from them on Tue, Mar 12, 6:44 PM:

Mar 17 2019, 11:33 PM · Unknown Object (Project)
avm99963 triaged T10: Error message reveals information about some internal data structure as Priority-3 priority.
Mar 17 2019, 11:33 PM · Unknown Object (Project)
avm99963 closed T9: Access to transcripts for other UB students as Fixed.

Just as an observation, this report was sent to pau@ub.edu on Feb 7, 2019, 12:43 AM, 20 days ago.

Mar 17 2019, 11:33 PM · Unknown Object (Project)
avm99963 added a comment to T9: Access to transcripts for other UB students.

I've been quite busy for the last week so I haven't been able to update this issue until today.

Mar 17 2019, 11:33 PM · Unknown Object (Project)
avm99963 renamed T9: Access to transcripts for other UB students from Accés a expedient d'altres alumnes de la UB to Access to transcripts for other UB students.
Mar 17 2019, 11:33 PM · Unknown Object (Project)
avm99963 set Reported to Feb 7 2019, 12:43 AM on T9: Access to transcripts for other UB students.
Mar 17 2019, 11:33 PM · Unknown Object (Project)
avm99963 triaged T9: Access to transcripts for other UB students as Priority-1 priority.
Mar 17 2019, 11:33 PM · Unknown Object (Project)

Jan 9 2019

avm99963 triaged T8: XSS and input validation vulnerability in "Competitions" section as Priority-1 priority.
Jan 9 2019, 12:29 AM · Unknown Object (Project)
avm99963 closed T8: XSS and input validation vulnerability in "Competitions" section as Verified.

On Tuesday, December 13, at 10:12 AM, a Jutge.org developer told me that this had been fixed, and I could verify it that same day.

Jan 9 2019, 12:29 AM · Unknown Object (Project)
avm99963 changed the visibility for T8: XSS and input validation vulnerability in "Competitions" section.
Jan 9 2019, 12:29 AM · Unknown Object (Project)

Jun 5 2018

avm99963 updated the task description for T7: Remote code execution and full access to database and codebase at offerplaying.com.
Jun 5 2018, 12:58 PM · Unknown Object (Project)
avm99963 triaged T7: Remote code execution and full access to database and codebase at offerplaying.com as Priority-0 priority.
Jun 5 2018, 12:56 PM · Unknown Object (Project)
avm99963 changed the visibility for F24: 172.zip.
Jun 5 2018, 12:53 PM

May 2 2018

avm99963 closed T6: Some users continue to receive email updates of some threads of a Google group after being removed from a group as Verified.
May 2 2018, 12:02 AM · Unknown Object (Project)

Apr 28 2018

avm99963 changed the visibility for T1: Students can see other student's personal information at accesuniversitat.gencat.cat.
Apr 28 2018, 2:25 PM · Unknown Object (Project)
avm99963 closed T1: Students can see other student's personal information at accesuniversitat.gencat.cat as Verified.

Yesterday at 14:26 someone from CESICAT called me in order to confirm that the issue was solved, as I had noticed the day before, when I updated this report.

Apr 28 2018, 2:25 PM · Unknown Object (Project)

Apr 26 2018

avm99963 added a comment to T1: Students can see other student's personal information at accesuniversitat.gencat.cat.

CESICAT hasn't replied yet to the message I sent them yesterday, but I have just seen that they the reproduction steps are no longer functional, so they must have fixed it or are actively working on fixing it.

Apr 26 2018, 6:46 PM · Unknown Object (Project)

Apr 25 2018

avm99963 created Vulnerability Reports Lifecycle.
Apr 25 2018, 11:25 PM · Unknown Object (Project)
avm99963 created Wiki.
Apr 25 2018, 11:25 PM
avm99963 updated the task description for T1: Students can see other student's personal information at accesuniversitat.gencat.cat.
Apr 25 2018, 10:16 PM · Unknown Object (Project)
avm99963 changed Reported from Apr 25 2018, 12:00 AM to Apr 25 2018, 5:52 PM on T1: Students can see other student's personal information at accesuniversitat.gencat.cat.
Apr 25 2018, 9:33 PM · Unknown Object (Project)
avm99963 changed the status of T1: Students can see other student's personal information at accesuniversitat.gencat.cat from New to Accepted.
Apr 25 2018, 9:14 PM · Unknown Object (Project)