Skip to main content

SSTI

bmdyy/tudo

·1653 words·8 mins
An OSWE-style source code review of the tudo web app, ending in a single all-in-one exploit script.

SSTI in ERPNext 12

·324 words·2 mins
Server-side template injection in ERPNext 12 leading to RCE.