xsspresso
xsspresso
Tags/ SSTI

SSTI

1 writeup tagged with SSTI

WebMediumLinux

HTB — Conversor

Unit conversion web app vulnerable to server-side formula injection, leading to arbitrary OS command execution.

#Formula Injection#SSTI#RCE
Oct 25, 2025HackTheBox