webmedium

SSTI hard

spbctf

Task: Advanced SSTI in Twig where password is not directly accessible in template context. Solution: Access nested config object via {{config.password}} to extract the flag.

$ ls tags/ techniques/
ssti_nested_variable_accessssti_config_extraction

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]