Security Researcher, Developer & Web3 Enthusiast.
Critical security vulnerabilities I've discovered and responsibly disclosed through various bug bounty programs.
Discovered a critical vulnerability allowing transfer from other accounts or demo accounts, and performing withdrawals from other people's accounts.
Discovered SSTI vulnerability with duplication allowing multiple remote code execution instances through template injection in web application framework.
Found stored XSS vulnerability in product review system that could be exploited to inject malicious scripts.