Loading HuntDB...

[h1-415 2020] Multiple vulnerabilities leading to leaking of secret user files

Critical
H
h1-ctf
Submitted None
Reported by nukedx

Vulnerability Details

Technical details and impact analysis

Server-Side Request Forgery (SSRF)
Hello, I'm just submitting both flags for CTF, will send my write up on hacker summary, since it's 7:00 am now :). Original flag for CTF: `h1ctf{y3s_1m_c0sm1c_n0w}` Extra flag for unintended account takeover: `h1ctf{wtf_1s_happ3ning_w1th_th1s_s1mulat1on}` Sincerely, @nukedx ## Impact By chaining multiple vulnerabilities attacker can leak secret user files.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Server-Side Request Forgery (SSRF)