Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Active Test / Server-Side Template Injection #72

Open
DeliciousBounty opened this issue Aug 31, 2022 · 3 comments
Open

Active Test / Server-Side Template Injection #72

DeliciousBounty opened this issue Aug 31, 2022 · 3 comments
Labels
New active check New active check

Comments

@DeliciousBounty
Copy link
Collaborator

Server-side template injection is a type of code injection that allows an attacker to execute malicious code on a web server by injecting template directives. By manipulating these directives, an attacker can gain access to sensitive data, execute arbitrary code, or even take control of the server.

Contributors are needed to help identify vulnerabilities that can be exploited using server-side template injection on a API.
More info:
https://book.hacktricks.xyz/pentesting-web/ssti-server-side-template-injection

@DeliciousBounty DeliciousBounty added the New active check New active check label Sep 1, 2022
@GuyL99 GuyL99 added the bounty label Sep 4, 2022
@vibhuti019
Copy link

Hi I would like to know more about the issue and work on same.

@DeliciousBounty
Copy link
Collaborator Author

Hello @vibhuti019 !
Thank you for getting involved. In this check, we want to check if the API is vulnerable to Template Injection.
Our checks are based on the OpenAPI specification of the tested API.
If you have more questions, feel free to send me an email, or join us on Discord.
:)
Discord: https://discord.gg/rxW4Mk4N
email: nathan.s@blstsecurity.com

@DeliciousBounty
Copy link
Collaborator Author

Hi I would like to know more about the issue and work on same.

Hey @vibhuti019, do you have some updates?

@RazMag RazMag removed the bounty label Oct 25, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
New active check New active check
Projects
None yet
Development

No branches or pull requests

4 participants