Progress

0 / 35 exploits found (this session). No flags - each working exploit ticks itself off below.

⬜ SSTI -> RCE (email signature)
⬜ OS command injection (diagnostics)
⬜ LFI / path traversal (KB / attachment download)
⬜ XXE (contact XML import)
⬜ SSRF (integration webhook / avatar fetch)
⬜ IDOR (read another user's ticket)
⬜ IDOR (read another user's inbox message)
⬜ Broken access control (admin console)
⬜ Insecure deserialization (draft cookie pickle)
⬜ JWT weak secret / alg=none -> admin
⬜ JWT kid path-traversal key confusion
⬜ Open redirect (SSO return_to)
⬜ CORS misconfiguration (reflected Origin + creds)
⬜ Stored XSS (ticket comment)
⬜ Reflected XSS (KB search)
⬜ DOM XSS (location.hash sink)
⬜ CSRF (change mail forwarding)
⬜ Host-header poisoning (reset link)
⬜ Predictable password-reset token
⬜ HTTP response header injection (CRLF)
⬜ Web cache poisoning (X-Forwarded-Host)
⬜ Mass assignment (role / is_admin)
⬜ Business logic (approve your own request)
⬜ Weak/reversible crypto (XOR backup key)
⬜ Source disclosure (.git / config backup)
⬜ Clickjacking (no anti-frame headers)
⬜ Secrets in client JS (desk.js token)
⬜ Verbose debug endpoint (config leak)
⬜ Unrestricted file upload (served as HTML)
⬜ User enumeration (reset differs)
⬜ SMTP header injection (Bcc via CRLF)
⬜ Client-side captcha bypass
⬜ Directory listing / index exposure
⬜ HTTP parameter pollution (sort)
⬜ SQL injection (user lookup)