webeasy

Студия анимаций (SVG Animation Studio)

duckerz

Task: SVG animation web app with file upload. Solution: XXE injection in SVG parser to read /app/flag.txt via SYSTEM entity.

$ ls tags/ techniques/
xxe_injectionsvg_xxelocal_file_read

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]