Yoon is actively conducting security research on open-source projects, focusing on identifying and reporting vulnerabilities to relevant vendors to ensure timely patches.

So far, Yoon has discovered a total of 20 CVEs, mainly in PHP open-source projects from SourceCodester. These vulnerabilities include Cross-Site Scripting (XSS), SQL Injection, and Unrestricted File Upload flaws.

When vendors don’t respond or are unwilling to fix these issues, Yoon takes the responsible step of publicly disclosing the vulnerabilities. This helps alert users to the potential risks associated with the affected products. By providing detailed proof-of-concept (POC) exploits, Yoon aims to help others understand and reproduce the vulnerabilities, ultimately raising security awareness and contributing to the overall improvement of the open-source community.

  • 20 CVEs Disclosed
CVEs
CVE-2024-6066CVE-2024-6067CVE-2024-6213CVE-2024-6214CVE-2024-6215
CVE-2024-6216CVE-2024-6217CVE-2024-6418CVE-2024-6419CVE-2024-7942
CVE-2024-7948CVE-2024-8140CVE-2024-8141CVE-2024-8142CVE-2024-8151
CVE-2024-8152CVE-2024-8153CVE-2024-8154CVE-2024-8170CVE-2024-8172