Martino Spagnuolo

Martino Spagnuolo

@r3verii

Italy 🇮🇹

Cybersec researcher, CTF player and bug hunter.

Places
📁 Home 📄 About
Files
📁 📂 bugbounty 2
📄 Zero‑Click ATO via Unbound Password‑R... 📄 From "Low-Impact" RXSS to Credential ...
📁 📂 ctf 2
📄 UTCTF 2024 Writeups 📄 CodeInTheDarkCTF 2023 writeups
📁 📂 cve 4
📄 The Forgotten Bug: How a Node.js Core... 📄 CSRF → XSS → Admin Takeover in listmo... 📄 3 Ways In: Exploiting WordPress Plugi... 📄 Znuny OTRS CVEs : CVE-2024-32491, CVE...
Bookmarks
🌐 LinkedIn 💻 GitHub 📡 RSS Feed
Activities
Home About GitHub
🔋 🔊 ⚙
Feb 27, 2026 cve

The Forgotten Bug: How a Node.js Core Design Flaw Enables HTTP Request Splitting

Deep dive into a TOCTOU vulnerability in Node.js's ClientRequest.path that bypasses CRLF validation and enables Header Injection and HTTP Request S...

Oct 18, 2025 bugbounty

Zero‑Click ATO via Unbound Password‑Reset Token in one of the world's largest gambling platforms

How a single-use OTP flow token not bound to the correct subject enabled a zero‑click account takeover.

Sep 8, 2025 cve

CSRF → XSS → Admin Takeover in listmonk (CVE-2025-58430)

A chain of issues in listmonk allows a Cross‑Site Request Forgery (CSRF) to trigger arbitrary JavaScript execution (XSS) in the admin’s browser, cu...

Aug 25, 2025 bugbounty

From "Low-Impact" RXSS to Credential Stealer: A JS-in-JS Walkthrough

From the classic “quote break” in a to a login takeover: step by step, I show how a “low-impact” RXSS becomes a real credential stealer.

Apr 8, 2025 cve

3 Ways In: Exploiting WordPress Plugins via File Upload and Deserialization

In this post, I break down three real-world vulnerabilities found in WordPress plugins — from unsafe deserialization to arbitrary file upload — and...

Apr 1, 2024 ctf

UTCTF 2024 Writeups

Writeups of some challenges from UTCTF 2024

Mar 20, 2024 cve

Znuny OTRS CVEs : CVE-2024-32491, CVE-2024-32492, CVE-2024-32493

In this post I detail two critical security flaws I discovered last year in the Znuny / OTRS ticket-ing system: a path-traversal file-upload bug th...

Oct 8, 2023 ctf

CodeInTheDarkCTF 2023 writeups

Writeups of some XSS challenges from CodeInTheDark CTF

© 2026 Martino Spagnuolo