webPromedium

Print on Demand (Печать по запросу)

duckerz

Task: Flask web app generating PDF certificates from user-supplied XML with an internal API holding the flag. Solution: Exploited XXE via insecure lxml parser (no_network=False, resolve_entities=True) to SSRF the internal Docker service, exfiltrating the admin UUID and flag through the generated PDF.

$ ls tags/ techniques/
xxe_to_ssrfdocker_service_discoveryxml_entity_injection

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups