The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Lab: Server-side Template Injection in an unknown language with a documented exploit (unintended?)

Low | Last updated: May 04, 2021 06:57AM UTC

Hi, I used a payload from this web https://book.hacktricks.xyz/pentesting-web/ssti-server-side-template-injection#handlebars-nodejs and it still considered that I completed the challenge even though I did not execute rm /home/carlos/morale.txt. Was thinking if this is considered unintended and should be corrected?

Hannah, PortSwigger Agent | Last updated: May 04, 2021 09:31AM UTC