$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: MailPulse email marketing platform with Smarty template engine editor and preview endpoint vulnerable to SSTI. Solution: Inject {system(\"cat /root/flag.txt\")} via template preview API to achieve RCE and read the flag, bypassing {fetch} tag path restrictions.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar