@jacopotediosi
Tech and cybersecurity enthusiast, pentester and bug bounty hunter
Signal
Signal
Follow this link to message on Signal.
Paypal
Paypal
Go to paypal.me/jacopotediosi and type in the amount. Since it’s PayPal, it's easy and secure. Don’t have a PayPal account? No worries.
Twitter
Twitter
Medium
Medium
Linkedin
Linkedin
Github
Github
Tech and cybersecurity enthusiast, pentester and bug bounty hunter - jacopotediosi
Telegram
Telegram
https://linktr.ee/jacopotediosi
Hackerone
Hackerone
Tech and cybersecurity enthusiast, pentester and bug bounty hunter - http://linktr.ee/jacopotediosi
Bugcrowd
Bugcrowd
Facebook
Facebook
PROJECT: Worldwide Akamai Cache Poisoning ($50K+ Bounty Earned)
PROJECT: Worldwide Akamai Cache Poisoning ($50K+ Bounty Earned)
Introduction And Context
PROJECT: #7 in the "Top 10 web hacking techniques of 2022"
PROJECT: #7 in the "Top 10 web hacking techniques of 2022"
Welcome to the Top 10 Web Hacking Techniques of 2022, the 16th edition of our annual community-powered effort to identify the most important and innovative web security research published in the last
PROJECT: CVE-2025-64187 (XSS in OctoPrint open source software)
PROJECT: CVE-2025-64187 (XSS in OctoPrint open source software)
### Impact OctoPrint versions up to and including 1.11.3 are affected by a vulnerability that allows injection of arbitrary HTML and JavaScript into Action Command notification and prompt popups...
PROJECT: CVE-2025-62169 (Lack of Authentication in OctoPrint-SpoolManager open source software)
PROJECT: CVE-2025-62169 (Lack of Authentication in OctoPrint-SpoolManager open source software)
### Summary The APIs of the OctoPrint-SpoolManager plugin (testing branch 1.8.0a2 and older, stable branch 1.7.7 and older) do not correctly enforce authentication or authorization checks. Impa...
PROJECT: CVE-2025-48879 (DoS in OctoPrint open source software)
PROJECT: CVE-2025-48879 (DoS in OctoPrint open source software)
### Impact OctoPrint versions up until and including 1.11.1 contain a vulnerability that allows any unauthenticated attacker to send a manipulated broken `multipart/form-data` request to OctoPri...
PROJECT: CVE-2025-48067 (File Exfiltration in OctoPrint open source software)
PROJECT: CVE-2025-48067 (File Exfiltration in OctoPrint open source software)
PROJECT: CVE-2025-32788 (Authentication Bypass in OctoPrint open source software)
PROJECT: CVE-2025-32788 (Authentication Bypass in OctoPrint open source software)
### Impact OctoPrint versions up until and including 1.10.3 contain a vulnerability that allows an attacker to bypass the login redirect and directly access the rendered HTML of certain frontend...
PROJECT: CVE-2024-51493 (Reauthentication Bypass in OctoPrint open source software)
PROJECT: CVE-2024-51493 (Reauthentication Bypass in OctoPrint open source software)
PROJECT: CVE-2024-49377 (Widespread XSS in OctoPrint open source software)
PROJECT: CVE-2024-49377 (Widespread XSS in OctoPrint open source software)
### Impact OctoPrint versions up until and including 1.10.2 are vulnerable to reflected XSS vulnerabilities through its Jinja2 template system, as this is not configured to enforce automatic esc...
PROJECT: CVE-2024-32977 (Authentication Bypass in OctoPrint open source software)
PROJECT: CVE-2024-32977 (Authentication Bypass in OctoPrint open source software)
### Impact OctoPrint versions up until and including 1.10.0 contain a vulnerability that allows an unauthenticated attacker to completely bypass the authentication **if the `autologinLocal` opti...
PROJECT: CVE-2024-28237 (Reflected XSS in OctoPrint open source software)
PROJECT: CVE-2024-28237 (Reflected XSS in OctoPrint open source software)
### Impact OctoPrint versions up until and including 1.9.3 contain a vulnerability that allows malicious admins to configure or talk a victim with administrator rights into configuring a webcam ...
PROJECT: CVE-2020-8115 (Reflected XSS in Revive Adserver open source software)
PROJECT: CVE-2020-8115 (Reflected XSS in Revive Adserver open source software)
At line 4381, $_SERVER['QUERY_STRING'], which is an untrusted user input, is assigned to the $dest variable. Then at lines 4386-4387 $dest is printed into HTML code in two separate places. PoC: ~~~~ curl "domain.com/www/delivery/afr.php?refresh=10000&\")',10000000);alert(1);setTimeout('alert(\"" <!DOCTYPE html PUBLIC '-//W3C//DTD XHTML 1.0 Transitional//EN'...
PROJECT: Made the web-based game "Chain Reaction"
PROJECT: Made the web-based game "Chain Reaction"
PROJECT: Founder of the (now closed) CTF platform "Webctf.IT"
PROJECT: Founder of the (now closed) CTF platform "Webctf.IT"
More from Linktree
Products
Link in bio + tools
Manage your social media
Grow and engage your audience
Monetize your following
Measure your success
Templates
Marketplace
Learn
Resources
How to use Linktree
Pricing
Link in bio + tools
Link in bio
Customize your Linktree
Link shortener
Create trackable, shareable short links
QR code generator
Turn links into scannable QR codes
Canva Background Editor
Import your custom designs from Canva into your profile
Linktree for every social platform
Grow and engage your audience everywhere
Instagram
TikTok
LinkedIn
X
Manage your social media
Schedule and auto-post
Hands-free, hassle-free social media planning
Instagram auto reply
Automated replies and DMs triggered by comments
AI content & caption generator
Instant AI-powered post ideas and captions
Hashtag generator
Trending hashtag suggestions for better reach
Social integration for every social platform
Plan, auto post, and share across all platforms
Instagram
TikTok
Facebook
Pinterest
LinkedIn
Threads
Youtube
Grow and engage your audience
Collect leads with contact forms
Turn visitors into subscribers
Manage and activate your audience
Organize, tag, and track contacts
Send contacts to email tools
Sync with Mailchimp, Klaviyo, Kit & more
Monetize your following
Earn with a Linktree Shop
Sell products and earn commission
Sell an online course
Create and sell your expertise easily
Host digital products
Sell digital products and build your email list
Earn by hosting sponsored links
Share brand offers and earn for every sign-up or sale
Get rewarded for growing your Linktree
Earn points, level up and unlock cash bonuses
Booked and paid, easily
Offer sessions and earn from your expertise
Measure your success
Social + link analytics
Track clicks, engagement and audience insights
Resources
Read our blog
All the latest tips, tricks and growth strategies
Success Stories
Real people, real results on Linktree
How to use Linktree
Linktree Help Centre
Get answers, guides and support