writeups.xyz writeups.xyz / Ngo Wei Lin (@Creastery)

Title Vulnerabilities Programs Authors
Send()-ing Myself Belated Christmas Gifts - GitHub.com's Environment Variables & GHES Shell
(CVE-2023-2017) Shopware 6 Server-side Template Injection (SSTI) via Twig Security Extension
CS-Cart PDF Plugin Unauthenticated Command Injection
Microsoft Azure Account Takeover via DOM-based XSS in Cosmos DB Explorer