$ cat writeup.md…
$ cat writeup.md…
miptctf
Task: Task board app with file uploads and admin bot. Solution: Exploited relative path script injection by uploading malicious JS as attachment, then tricking admin bot to visit crafted URL that loads the attachment as script.js, exfiltrating /api/secret via image beacon.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar