webProeasy

Lab 243 — VendorNest — SSTI in Product Descriptions via Blade Template Engine

hackadvisor

Task: Multi-vendor marketplace (PHP/Blade) where sellers can create products with rich descriptions rendered through a Blade template engine. Solution: Injected @php directive into product description to achieve SSTI → RCE, bypassed decoy flags, read /root/flag.txt.

$ ls tags/ techniques/
decoy_flag_recognitionssti_blade_php_directiverce_via_php_directiveshell_exec_command_execution

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups