tl;dr
- Json_Interoperability -
/verify_roles?role=supersuperuseruser\ud800","name":"admin - Prototype_Pollution -
{"constructor":{"prototype":{"test":"123"}}}in config-handler
tl;dr
/verify_roles?role=supersuperuseruser\ud800","name":"admin{"constructor":{"prototype":{"test":"123"}}} in config-handlertl;dr
sha256('')./api/flag and send it to attacker server.tl;dr
tl;dr
tl;dr
tl;dr
tl;dr
tl;dr
tl;dr
tl;dr