$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: Django analytics platform with Custom Report Builder API that passes user-controlled metadata field names to QuerySet.values(), generating unescaped SQL column aliases for JSONField extraction. Solution: exploit CVE-2024-42005 by injecting double quotes into the field name to break out of the AS alias, then use UNION-based SQLite injection with error-based extraction to enumerate tables and read the flag from secret_flags.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar