• Skip to primary navigation
  • Skip to content
  • Skip to footer
./Writeups
      Alvaro Balada

      Alvaro Balada

      Trying to make a living in security research.

      • YouTube
      • Medium
      • LinkedIn
      • X/Twitter
      Grafana Full read SSRF and Account Takeover: CVE-2025-4123

      Grafana Full read SSRF and Account Takeover: CVE-2025-4123

      ... This might not seem dangerous on its own, but this type of bug was the starting point for uncovering two separate vulnerabilities: a Full Read SSRF and an account...

      Moodle Stored XSS: CVE-2025-26529

      Moodle Stored XSS: CVE-2025-26529

      I’m excited to explain my process and methodology for finding my first CVE vulnerability (CVE-2025–26529) in an open source project! ...

      • Follow:
      • Feed
      © 2025 ./Writeups. Powered by Jekyll & Minimal Mistakes.