webPromedium

BillForge

hackadvisor

Task: Invoicing platform (BillForge) with wkhtmltopdf-based PDF export where notes field is rendered as raw HTML in PDF but escaped in web view. Solution: Injected iframe pointing to http://localhost:3001/flag in notes field, exploiting SSRF via wkhtmltopdf to access internal flag service.

$ ls tags/ techniques/
ssrf_via_wkhtmltopdfinternal_service_accessanti_honeypot_awarenesshtml_injection_in_pdflocalhost_ipv6_bypassdifferential_rendering

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups