webPromedium
Lab 133 — MailForge — SSTI via Handlebars Template Preview
hackadvisor
Task: Express.js email marketing platform with Handlebars template preview that compiles user-supplied templates server-side. Solution: SSTI via Handlebars prototype chain traversal (String.prototype.sub → Function constructor) to execute process.env and extract FLAG.
$ ls tags/ techniques/
decoy_flag_recognitionhandlebars_ssti_prototype_chainprocess_env_disclosure
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]SendForge— hackadvisor
- [web][Pro]Lab 237 — MailCraft — SSTI in Email Template Preview— hackadvisor
- [web][Pro]Lab 213 — PingCraft — SSTI via Template Preview Rendering— hackadvisor
- [web][Pro]MailPilot — SSTI in Template Preview— hackadvisor
- [web][Pro]Lab 225 — MailPulse — SSTI in Campaign Template Preview— hackadvisor