webPromedium

Lab 213 — PingCraft — SSTI via Template Preview Rendering

hackadvisor

Task: Express.js notification platform with template preview endpoint using JavaScript Function constructor for server-side template literal evaluation. Solution: SSTI via ${} expressions in POST /api/templates/preview, escalated to process.env disclosure via ${JSON.stringify(process.env)} to extract FLAG from environment variables.

$ ls tags/ techniques/
decoy_flag_recognitionprocess_env_disclosuressti_js_template_literals

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups