$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: Flask/Jinja2 email marketing platform with template preview feature that renders user-supplied templates via render_template_string(). Solution: Exploited SSTI through lipsum.__globals__['os'].popen() to read /tmp/flag.txt.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar