webPromedium

ContentForge

hackadvisor

Task: ContentForge headless CMS with editable email templates using lodash template engine, server-side rendered via preview API. Solution: Bypass input filter (which blocks require/execSync but not process.env) by injecting <%= JSON.stringify(process.env) %> to dump environment variables containing the flag.

$ ls tags/ techniques/
decoy_flag_recognitionprocess_env_disclosurelodash_template_sstiinput_filter_bypass

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups