email-functionality

1 article
sort: new top best
clear filter
0 7/10

A Flask/Jinja2 template injection vulnerability was discovered in an email generation utility that evaluated user input in email subject fields. The attacker exploited Python object introspection through Jinja2 syntax to access the file class and read sensitive files including configuration files with API keys and encryption keys from a GCE instance.

Flask Jinja2 Django Bugcrowd AkShAy KaTkAr Wappalyzer GCE
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 23 hours ago · details