Maxim Masiutin
Software Developer | Cybersecurity Professional
Connect
- LinkedInProfessional profile and career history.
- GitHubOpen source projects and contributions.
- ORCIDResearcher identifier linking publications across platforms.
- Stack OverflowProgramming Q&A contributions.
- Root MeCybersecurity challenges and CTF platform.
- WikipediaContributor to English Wikipedia and other Wikimedia projects.
Projects
- Stockfish Top Authors and MethodsAnalysis of Stockfish chess engine contributors ranked by successful tests on Fishtest. Covers 6 years of development history with method definitions.
- TinyWeb CGI Command Injection (CVE Request 1971570)OS command injection vulnerability in TinyWeb HTTP Server CGI handling. Fixed in version 1.98. Published December 27, 2025.
- TinyWeb CRLF Injection (CVE-2024-5193)CRLF injection vulnerability in TinyWeb HTTP Server allowing HTTP header injection. Fixed in version 1.99. Published January 5, 2026.
- CVE-2024-3677 Does NOT Affect TinyWebSecurity notice clarifying that CVE-2024-3677 (WordPress plugin XSS) does not affect TinyWeb HTTP Server. Published January 5, 2026.
- FARM Archive (external)Archive of the Moldovan Automobile Federation (FARM) with motorsport regulations, competition protocols, and racing event documentation from 2007-2008.
Publications
- Alternative Androgen PathwaysWikiJournal of Medicine, 2023. DOI: 10.15347/WJM/2023.003
- Letter to the Editor: Adrenocortical Hormone Abnormalities in Chronic ProstatitisUrology (Elsevier), 2022. DOI: 10.1016/j.urology.2022.07.038
Tools
- List ConverterBrowser-based utility to convert newline-separated lists to comma-separated values.
Security Advisories
- CVE Request 1971570 - TinyWeb CGI Command InjectionOS command injection in TinyWeb HTTP Server CGI handling. CVSS 8.1 High. Fixed in v1.98.
- CVE-2024-5193 - TinyWeb CRLF InjectionHTTP header injection via CRLF in TinyWeb HTTP Server. CVSS 6.1 Medium. Fixed in v1.99.
- CVE-2024-3677 ClarificationSecurity notice: CVE-2024-3677 (WordPress plugin XSS) does not affect TinyWeb HTTP Server.