webPromedium
BillForge
hackadvisor
Task: Invoicing platform (BillForge) with wkhtmltopdf-based PDF export where notes field is rendered as raw HTML in PDF but escaped in web view. Solution: Injected iframe pointing to http://localhost:3001/flag in notes field, exploiting SSRF via wkhtmltopdf to access internal flag service.
$ ls tags/ techniques/
ssrf_via_wkhtmltopdfinternal_service_accessanti_honeypot_awarenesshtml_injection_in_pdflocalhost_ipv6_bypassdifferential_rendering
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Lab 25 — DocuForge — RCE via Dompdf Font Cache Exploitation— hackadvisor
- [web][Pro]Lab 58 — ReportForge — SSRF via PDF Export Logo URL— hackadvisor
- [web][Pro]Lab 345 — PrintForge — RCE via Ghostscript Command Injection— hackadvisor
- [web][Pro]Lab 13 — WebForge — Insecure Deserialization in Config Import— hackadvisor
- [web][Pro]SendForge— hackadvisor