$ cat writeup.md…
$ cat writeup.md…
bug-makers
Task: Symfony 8 news portal accidentally left in DEV mode (APP_DEBUG=1) with the Web Profiler exposed; the flag lives in a draft article behind an admin-only RS256-JWT API. Solution: use /_profiler/open with a project-relative path for arbitrary file read, leak the encrypted JWT private key, decrypt it with JWT_PASSPHRASE from /_profiler/phpinfo, forge an admin RS256 token, and read the draft article.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar