Martino Spagnuolo

Martino Spagnuolo

@r3verii

Italy ๐Ÿ‡ฎ๐Ÿ‡น

Cybersec researcher, CTF player and bug hunter.

Places
๐Ÿ“ Home ๐Ÿ“„ About
Files
๐Ÿ“ ๐Ÿ“‚ bugbounty 2
๐Ÿ“„ Zeroโ€‘Click ATO via Unbound Passwordโ€‘R... ๐Ÿ“„ From "Low-Impact" RXSS to Credential ...
๐Ÿ“ ๐Ÿ“‚ ctf 2
๐Ÿ“„ UTCTF 2024 Writeups ๐Ÿ“„ CodeInTheDarkCTF 2023 writeups
๐Ÿ“ ๐Ÿ“‚ cve 5
๐Ÿ“„ HAProxy HTTP/3 -> HTTP/1 Desync: Cros... ๐Ÿ“„ The Forgotten Bug: How a Node.js Core... ๐Ÿ“„ CSRF โ†’ XSS โ†’ Admin Takeover in listmo... ๐Ÿ“„ 3 Ways In: Exploiting WordPress Plugi... ๐Ÿ“„ Znuny OTRS CVEs : CVE-2024-32491, CVE...
Bookmarks
๐ŸŒ LinkedIn ๐Ÿ’ป GitHub ๐Ÿ“ก RSS Feed
Activities
Home About GitHub
๐Ÿ”‹ ๐Ÿ”Š โš™
Apr 14, 2026 cve

HAProxy HTTP/3 -> HTTP/1 Desync: Cross-Protocol Smuggling via a Standalone QUIC FIN (CVE-2026-33555)

One zero-byte QUIC packet is enough to desynchronize HAProxy's backend connection pool and smuggle HTTP requests across unrelated users โ€” even user...

Feb 27, 2026 cve

The Forgotten Bug: How a Node.js Core Design Flaw Enables HTTP Request Splitting

Deep dive into a TOCTOU vulnerability in Node.js's ClientRequest.path that bypasses CRLF validation and enables Header Injection and HTTP Request S...

Oct 18, 2025 bugbounty

Zeroโ€‘Click ATO via Unbound Passwordโ€‘Reset Token in one of the world's largest gambling platforms

How a single-use OTP flow token not bound to the correct subject enabled a zeroโ€‘click account takeover.

Sep 8, 2025 cve

CSRF โ†’ XSS โ†’ Admin Takeover in listmonk (CVE-2025-58430)

A chain of issues in listmonk allows a Crossโ€‘Site Request Forgery (CSRF) to trigger arbitrary JavaScript execution (XSS) in the adminโ€™s browser, cu...

Aug 25, 2025 bugbounty

From "Low-Impact" RXSS to Credential Stealer: A JS-in-JS Walkthrough

From the classic โ€œquote breakโ€ in a to a login takeover: step by step, I show how a โ€œlow-impactโ€ RXSS becomes a real credential stealer.

Apr 8, 2025 cve

3 Ways In: Exploiting WordPress Plugins via File Upload and Deserialization

In this post, I break down three real-world vulnerabilities found in WordPress plugins โ€” from unsafe deserialization to arbitrary file upload โ€” and...

Apr 1, 2024 ctf

UTCTF 2024 Writeups

Writeups of some challenges from UTCTF 2024

Mar 20, 2024 cve

Znuny OTRS CVEs : CVE-2024-32491, CVE-2024-32492, CVE-2024-32493

In this post I detail two critical security flaws I discovered last year in the Znuny / OTRS ticket-ing system: a path-traversal file-upload bug th...

Oct 8, 2023 ctf

CodeInTheDarkCTF 2023 writeups

Writeups of some XSS challenges from CodeInTheDark CTF

ยฉ 2026 Martino Spagnuolo