webeasy

SSTI easy

spbctf

Task: SSTI vulnerability in Twig template engine with user input rendered without filtering. Solution: Access the password variable in template context using {{password}} payload.

$ ls tags/ techniques/
ssti_context_variable_access

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]