(July 2, 2022, 07:17 PM)Erik Wrote: You can access admin dashboard with admin' -- - as the username No idea how to proceed though, didn't find anything to do from there
Found those two things but not sure if that's any useful yet : https://github.com/mpdf/mpdf/issues/949 https://pentest.co.uk/labs/leveraging-xss-to-get-rce-in-textpattern/ How can this be harder than Carpe Diem, fuck me
[quote="Exa" pid="117869" dateline="1656792178"]When I'm adding (and encoding) to the pdf parameter of /admin/download.php, I'm getting an incoming request to my Python server.[/quote]From you or from the taget ?