RESEARCH ARCHIVE18 Research • 31 Writeups

Phat Mai

Security Researcher & Penetration Tester

Focusing on vulnerability analysis, source code review, and offensive security research.

18
Research Advisories
31
CTF & Lab Writeups
49
Total Publications
phatmai@research-node:~
$whoami

Phat Mai — Security Researcher & Pentester

$cat /etc/security/focus.cfg
Web Application Vulnerability Research
Source Code Audit & Java Deserialization
Active Directory & Penetration Testing
status: active research
49 articles published
Featured Research
CVE-2026-404782026-06-04

CVE-2026-40478 Thymeleaf Template Injection: From Sandbox Bypass to Unauthenticated RCE

# CVE-2026-40478 Thymeleaf Template Injection: From Sandbox Bypass to Unauthenticated RCE ![image](https://hackmd.io/uploads/BkLrCXJZzg.png) ## Overview ...

# ADVISORY_METADATA
TYPE: Vulnerability Disclosure
SCOPE: Source-to-Sink Flow
SEVERITY: CRITICAL
READ TIME: 6 min read
Vulnerability Research

Vulnerability Research (18 Articles)

Root cause analysis, CVE disclosures, and exploit mechanics.

View all 18 Research Papers →
CVE-2026-40478critical
2026-06-046 min read

CVE-2026-40478 Thymeleaf Template Injection: From Sandbox Bypass to Unauthenticated RCE

# CVE-2026-40478 Thymeleaf Template Injection: From Sandbox Bypass to Unauthenticated RCE ![image](https://hackmd.io/uploads/BkLrCXJZzg.png) ## Overview ...

CVE-2026-3359critical
2026-05-166 min read

CVE-2026-3359 WordPress Form Maker by 10Web Plugin <= 1.15.42 is vulnerable to a high priority SQL Injection

# Critical SQL Injection (CVE-2026-3359) in WordPress Form Maker by 10Web ![image](https://hackmd.io/uploads/rJC0RXuRbg.png) ## Overview Published: ...

CVE-2026-2628critical
2026-05-038 min read

CVE-2026-2628 WordPress All-in-One Microsoft 365 &amp; Entra ID / Azure AD SSO Login Plugin <= 2.2.5 is vulnerable to a high priority Bypass Vulnerability

# WordPress All-in-One Microsoft 365 &amp; Entra ID / Azure AD SSO Login Plugin <= 2.2.5 is vulnerable to a high priority Bypass Vulnerability ![image](https...

CVE-2026-2942critical
2026-04-126 min read

CVE-2026-2942 WordPress ProSolution WP Client Plugin <= 1.9.9 is vulnerable to a high priority Arbitrary File Upload

## CVE-2026-2942 WordPress ProSolution WP Client Plugin <= 1.9.9 is vulnerable to a high priority Arbitrary File Upload ![image](https://hackmd.io/uploads/H1...

CVE-2026-3658high
2026-04-127 min read

CVE-2026-3658 WordPress Simply Schedule Appointments Plugin <= 1.6.10.0 is vulnerable to a high priority SQL Injection

## CVE-2026-3658 WordPress Simply Schedule Appointments Plugin <= 1.6.10.0 is vulnerable to a high priority SQL Injection ![image](https://hackmd.io/uploads/...

CVE-2026-1581high
2025-12-306 min read

CVE-2026-1581 WordPress wpForo Forum Plugin is vulnerable to a high priority SQL Injection

# CVE-2026-1581 WordPress wpForo Forum Plugin is vulnerable to a high priority SQL Injection ![image](https://hackmd.io/uploads/BJipTiSdbe.png) ## Overvie...

Focus Areas & Skills

Technical Focus & Domains

Core technical capabilities and research focus.

Vulnerability Research

Auditing open-source plugins, CMS extensions, and web applications, followed by responsible disclosure and patch analysis.

CVE DisclosuresPatch DiffingLogic Flaws

Source Code Review

Manual static code analysis across Java, PHP, Python, and JavaScript to identify source-to-sink data flows and unsafe patterns.

Taint AnalysisJava / PHP / PythonCode Auditing

Java Deserialization

Studying Java object serialization vulnerabilities, gadget chains in popular libraries (Commons Collections), and ysoserial payloads.

ysoserialCC3 / CC5URLDNS Chain

Active Directory Assessment

Practicing internal infrastructure testing techniques including Kerberoasting, AS-REP Roasting, and domain privilege escalation.

KerberoastingAS-REP RoastingActive Directory

Web Security Testing

Identifying and reproducing common web vulnerabilities such as SQL Injection, SSTI (Velocity/Thymeleaf), SSRF, and File Upload.

SQL InjectionSSTISSRFFile Upload

Technical Writeups

Documenting step-by-step reproducible methodology, technical analysis, and mitigation advice for researchers and developers.

Proof of ConceptCTF WalkthroughsRemediation
Technical Writeups

Technical Writeups & Labs (31 Writeups)

Walkthroughs and notes from CTFs, security labs, and pentesting platforms.

View all 31 Writeups →
CTF
2025-12-1910 min read

Velocity Server Side Template Injection Challenge

# Velocity Server Side Template Injection Challenge ### Tổng quan về lab Velocity SSTI Đây là một lab mình thiết kế ra để demo và học về SSTI. Bên trong l...

Writeup
2025-12-175 min read

Tryhackme Hammer challenge WriteUp

# TryHackMe Hammer Web Challenge WriteUp ![image-14](https://hackmd.io/uploads/S1-1mNlzbl.png) ### Enumeration ![image-15](https://hackmd.io/uploads/r...

Writeup
2025-12-164 min read

IredTeam AS-REP Roasting

# IredTeam AS-REP Roasting ### AS-REP là gì? AS-REP (viết tắt của Authentication Service Reply) là một thông điệp trong giao thức xác thực Kerberos. Đây ...

Writeup
2025-12-1511 min read

ServerSide Template Injection (SSTI) Lab

# ServerSide Template Injection (SSTI) Lab ### SSTI là gì Server-Side Template Injection (SSTI) là một lỗ hổng bảo mật web nghiêm trọng cho phép kẻ tấn cô...

PortSwigger
2025-12-1416 min read

GraphQL API Vulnerability

# GraphQL API Vulnerability PortSwigger Challenge ### Overview về GraphQL GraphQL là một ngôn ngữ truy vấn cho API (Query Language for APIs) và cũng là mộ...

PortSwigger
2025-12-1311 min read

PortSwigger CORS (Cross-Origin Resource Sharing) challenge WriteUp

# PortSwigger CORS (Cross-Origin Resource Sharing) challenge WriteUp ### Overview về CORS #### CORS là gì? Vì sao lại xuất hiện - CORS (Cross-Origin Reso...

Publication Activity

Publication Cadence

Release timeline and article cadence across recent months.

49Total Releases
Less
More