A Flask 1.1.1 application that builds a Jinja2 template from the name query parameter, so template expressions in it are evaluated on the server (SSTI), up to running Python and shell commands.
Pas commencéDockercommit b88eb52x86_64 · aarch64Secret
Exploit the Jinja2 template injection to run commands on the server and read the flag.
Le brief de ce lab se trouve dans son dépôt.