webPromedium

Lab 247 — PulseGuard — SSTI in Webhook Notification Templates

hackadvisor

Task: Express.js uptime monitoring platform with Liquid template support in webhook notifications. Solution: SSTI via LiquidJS include tag to read /proc/self/environ and extract FLAG from environment variables.

$ ls tags/ techniques/
ssti_liquidjslfi_via_include_tagproc_environ_disclosure

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups