[h1-415 2020] Multiple vulnerabilities leading to leaking of secret user files
Critical
H
h1-ctf
Submitted None
Actions:
Reported by
nukedx
Vulnerability Details
Technical details and impact analysis
Hello,
I'm just submitting both flags for CTF, will send my write up on hacker summary, since it's 7:00 am now :).
Original flag for CTF: `h1ctf{y3s_1m_c0sm1c_n0w}`
Extra flag for unintended account takeover: `h1ctf{wtf_1s_happ3ning_w1th_th1s_s1mulat1on}`
Sincerely,
@nukedx
## Impact
By chaining multiple vulnerabilities attacker can leak secret user files.
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Server-Side Request Forgery (SSRF)