webeasy

SWE Intern at Girly Pop Inc — Writeup

scarlet

Task: Flask web application JWT Studio with file viewing endpoint. Solution: Exploited LFI via path traversal in the page parameter to read README.md containing the flag.

$ ls tags/ techniques/

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]