$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: Invoicing platform (BillForge) with wkhtmltopdf-based PDF export where notes field is rendered as raw HTML in PDF but escaped in web view. Solution: Injected iframe pointing to http://localhost:3001/flag in notes field, exploiting SSRF via wkhtmltopdf to access internal flag service.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar