tl;dr
/source
to get the source- Access local host from
dev_test
using SSRF - SQLI to get the flag path a nd LFI to get the flag
tl;dr
/source
to get the sourcedev_test
using SSRFtl;dr
tl;dr
/verify_roles?role=supersuperuseruser\ud800","name":"admin
{"constructor":{"prototype":{"test":"123"}}}
in config-handlertl;dr
sha256('')
./api/flag
and send it to attacker server.tl;dr
tl;dr
tl;dr
tl;dr
tl;dr
tl;dr