$ cat writeup.md…
$ cat writeup.md…
duckerz
Task: Flask web app generating PDF certificates from user-supplied XML with an internal API holding the flag. Solution: Exploited XXE via insecure lxml parser (no_network=False, resolve_entities=True) to SSRF the internal Docker service, exfiltrating the admin UUID and flag through the generated PDF.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar