SecureBank's advanced search feature boasts dynamic template processing for personalized results. But when user input meets template engines without proper sanitization, the server might just execute more than they bargained for. 🚀 Time to turn their templates against them!
Launch your dedicated AWS machine to begin hacking
Server-Side Template Injection is a critical vulnerability that occurs when user input is embedded into template engines without proper sanitization. This challenge teaches you how to exploit SSTI vulnerabilities to achieve remote code execution and access sensitive system information.
SecureBank's search functionality uses dynamic template rendering with user input. Your mission is to exploit this Server-Side Template Injection vulnerability to execute code on the server and extract the hidden flag from the system environment.
Sign-in to your account to access your hacking courses and cyber security labs.
Access all hacking courses and cyber security labs.