webProeasy

Lab 58 — ReportForge — SSRF via PDF Export Logo URL

hackadvisor

Task: ReportForge business analytics platform with PDF export and company logo URL branding setting — SSRF via server-side logo fetch. Solution: set logo URL to http://localhost:3001/ to discover internal endpoints, then http://localhost:3001/flag to extract the flag embedded in the exported PDF content stream.

$ ls tags/ techniques/
internal_service_enumerationdecoy_flag_avoidancessrf_via_pdf_logo_urlpdf_content_stream_glyph_decoding

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups