Lab: Server-side template injection using documentation

We see the following web page

We login with the credentials we have

With this account, we can edit the posts

Trying payloads. We got that:

Let's try with Java

Throwing error, we see Java FreeMarker using

Using code execution

So we can remove morale.txt

Última actualización