$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: DataPulse analytics dashboard with SVG avatar upload processed server-side via libxmljs2 with entity resolution enabled. Solution: XXE injection in SVG file to read local files, discovered .env config at /app/data/.env revealing confidential report path, then read flag from /app/data/.reports/confidential.txt.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar