$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: Flask CMS with page editor supporting template variables. Solution: Discovered SSTI in page content via differential analysis (pages render templates, posts don't), exploited via lipsum.__globals__ to achieve RCE and read /root/flag.txt.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar