xsspresso
xsspresso
Tags/ Flask

Flask

1 writeup tagged with Flask

WebEasyLinux

HTB — Titanic

Flask app path traversal via download endpoint reads arbitrary files including admin credentials. Magick ImageMagick CVE-2024-41817 for root shell.

#Path Traversal#Flask#ImageMagick
Feb 16, 2025HackTheBox