Mohammad Jafari (h4shur)
Mohammad Jafari, widely known in the cybersecurity community by the pseudonym h4shur, is an independent cybersecurity researcher, vulnerability analyst, and programmer based in Iran. His work focuses exclusively on the identification, documentation, and responsible disclosure of security flaws in content management systems, web applications, mobile applications, and enterprise software. His findings are extensively documented and verified in national and international cybersecurity databases.[1]
Methodology and Scope of Work
Operating as an independent security researcher and bug hunter, Jafari employs standard penetration testing methodologies. This includes source code review, input/output validation, and reverse engineering to identify logical and implementation flaws. The primary objective of this work is to provide actionable intelligence and Proof of Concept (PoC) data to software vendors and the security community, facilitating patch development and the creation of defensive rules (e.g., Web Application Firewall signatures).
Notable Vulnerability Disclosures
A significant portion of Jafari's professional recognition stems from the discovery and formal registration of critical vulnerabilities that have resulted in the issuance of CVE identifiers and the release of security patches.
Critical Vulnerability: CVE-2021-47965
The most prominent documented discovery by this researcher is an unrestricted file upload vulnerability in the WordPress "WP Super Edit" plugin (version 2.5.4 and earlier).[2]
- Technical Mechanism: The vulnerability resides in the plugin's FCKeditor component, allowing attackers to upload dangerous file types without validation via the filemanager upload endpoint.[3]
- Impact Severity: Successful exploitation leads to Remote Code Execution (RCE) and complete system compromise. The CVSS score for this vulnerability is rated 9.8 (Critical) by authoritative bodies.[4][5]
- Widespread Verification: This discovery has been verified, documented, and credited to h4shur as the "Finder" by numerous global threat intelligence platforms and databases, including:
- National Vulnerability Database (NIST NVD)[6] - GitHub Security Advisory[7] - WPScan Vulnerability Database[8] - Wordfence Threat Intelligence[9] - VulnCheck[10] - Rapid7 Vulnerability Database[11] - SentinelOne Vulnerability Database[12] - Additional technical analyses by Patchstack[13], ZeroPath[14], FreshySites[15], NextGuardHQ[16], The Hacker Wire[17], DataHouse[18], Redsauce[19], and Fused[20].
Adobe Connect Vulnerabilities
Beyond the WordPress ecosystem, this researcher's work has led to the identification and formal registration of multiple vulnerabilities in the Adobe Connect web conferencing software:
- CVE-2023-22232 (Local File Disclosure): Identification of an Improper Access Control vulnerability leading to Local File Disclosure (LFD) in Adobe Connect versions 11.4.5, 12.1.5, and earlier.[21] This discovery resulted in formal registration in the NIST database[22] and triggered security advisories from entities such as Check Point[23], INCIBE-CERT[24], OpenCVE[25], Strix AI[26], and Strobes VI[27]. The Proof of Concept (PoC) for this vulnerability is integrated into automated scanning templates like Nuclei[28] and documented in exploit databases.[29][30]
- Adobe Connect 10 Username Disclosure: Identification of a Username Disclosure and Local Route Disclosure vulnerability in version 10 of the software. Technical documentation for this finding is registered in Exploit-DB[31] and Packet Storm[32] under the author identifier h4shur.
Other Documented Disclosures in Mobile and Core CMS Applications
The researcher's scope extends to identifying security flaws in widely used mobile applications and core CMS architectures:
- Telegram Android Denial of Service: Discovery and documentation of a Denial of Service (DoS) vulnerability in version 8.4.4 of the Telegram messaging application for Android. The Proof of Concept was published on Packet Storm (ID 166008) and ResearchGate.[33]
- WordPress 6.4.3 Username Disclosure: Identification of a flaw leading to Username Disclosure in WordPress core version 6.4.3. Technical documentation for this finding is registered in Packet Storm under ID 177227.[34]
Academic and Professional Profiles
To maintain transparency and share research with the scientific and cybersecurity communities, Jafari maintains active, verifiable profiles on the following networks:
- Vulnerability Databases and Threat Intelligence:
- Academic and Research Networks:
References
- ↑ https://www.cve.org/CVERecord?id=CVE-2021-47965
- ↑ https://nvd.nist.gov/vuln/detail/cve-2021-47965
- ↑ https://www.vulncheck.com/advisories/wordpress-plugin-wp-super-edit-unrestricted-file-upload
- ↑ https://github.com/advisories/GHSA-7wfw-gfch-rf74
- ↑ https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-super-edit/wp-super-edit-254-unauthenticated-arbitrary-file-upload
- ↑ https://nvd.nist.gov/vuln/detail/cve-2021-47965
- ↑ https://github.com/advisories/GHSA-7wfw-gfch-rf74
- ↑ https://wpscan.com/vulnerability/d7900aaf-6604-4fde-882c-29e46c093259/
- ↑ https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-super-edit/wp-super-edit-254-unauthenticated-arbitrary-file-upload
- ↑ https://www.vulncheck.com/advisories/wordpress-plugin-wp-super-edit-unrestricted-file-upload
- ↑ https://www.rapid7.com/db/vulnerabilities/cve-2021-47965/
- ↑ https://www.sentinelone.com/vulnerability-database/cve-2021-47965/
- ↑ https://patchstack.com/database/wordpress/plugin/wp-super-edit/vulnerability/wordpress-wp-super-edit-plugin-2-5-4-unauthenticated-arbitrary-file-upload-vulnerability
- ↑ https://zeropath.com/blog/cve-2021-47965-wp-super-edit-unrestricted-file-upload
- ↑ https://freshysites.com/security-bulletins/wp-super-edit-plugin-vulnerability-cve-2021-47965/
- ↑ https://nextguardhq.com/en/vulnerabilities/cve-2021-47965-wp-super-edit-wp-super-edit
- ↑ https://www.thehackerwire.com/vulnerability/CVE-2021-47965/
- ↑ https://datahouse.net/b/cve-2021-47965
- ↑ https://www.redsauce.net/en/cves/CVE-2021-47965
- ↑ https://www.fused.com/wordpress-vulnerabilities/plugins/wp-super-edit/cve-2021-47965
- ↑ https://www.cve.org/CVERecord?id=CVE-2023-22232
- ↑ https://nvd.nist.gov/vuln/detail/cve-2023-22232
- ↑ https://advisories.checkpoint.com/defense/advisories/public/2024/cpai-2023-1869.html/
- ↑ https://www.incibe.es/index.php/en/incibe-cert/early-warning/vulnerabilities/cve-2023-22232
- ↑ https://opencve.alliance.unm.edu/cve/CVE-2023-22232
- ↑ https://www.strix.ai/cve/CVE-2023-22232
- ↑ https://strobes.co/vi/cve/CVE-2023-22232/
- ↑ https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-22232.yaml
- ↑ https://www.exploit-db.com/exploits/51327
- ↑ https://packetstorm.news/files/id/171390
- ↑ https://www.exploit-db.com/exploits/49550
- ↑ https://packetstorm.news/files/id/161345
- ↑ https://packetstorm.news/files/id/166008
- ↑ https://packetstorm.news/files/id/177227

