xsspresso
xsspresso
Tags/ Ruby

Ruby

1 writeup tagged with Ruby

WebEasyLinux

HTB — Precious

Pdfkit CVE-2022-25765 SSRF/command injection via URL parameter in PDF generation endpoint. Ruby bundler YAML deserialization for root.

#Pdfkit#CVE-2022-25765#YAML Deserialization
Jan 19, 2025HackTheBox