Medium
Linux
Locked
FireFlow Writeup - HackTheBox
Flask web app vulnerable to SSTI via user-controlled templates. Exploit Jinja2 injection to achieve RCE, then escalate privileges on Linux for root.