(VietNamese) CVE Analysis Authenticated Stored Blind SQL Injection via Custom Field Table Identifier
Vulnerability Summary Field Value OpenSource InvoicePlane Github Invoiplane Opensource CVSS Score 5.5 (Medium) Attack Vector Authenticated Administrator CVSS Vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:L CWE CWE-89, CWE-20 Vulnerability Type Authenticated Stored Blind SQL Injection via Custom Field Table Identifier Affected Versions v1.7.2-beta-1 Researcher capt-bl4ck0ut Affected endpointsVấn đề là tấn công SQLi lưu trữ, vì vậy có hai nhóm điểm cuối liên quan: 12...
(VietNamese) WordPress POP Chain
IntroductionTrong quá trình thực hiện task nghiên cứu về POP Chain trên WordPress dưới sự hướng dẫn của người anh, mình đã phát hiện ra lỗ hổng Insecure Deserialization bắt nguồn từ việc plugin xử lý dữ liệu đầu vào thiếu an toàn. Hiện tại, PoC mới chỉ chứng minh được khả năng khởi tạo class bất kỳ và bypass filter, chưa đạt đến mức thực thi shell (RCE) trên máy chủ. Vì vậy, hướng tiếp cận sắp tới là rà soát các POP Chain trong WordPress Core để mở rộng phạm vi khai thác. Setup Lab Enviroment...
(VietNamese) CVE-2026-34612 Remote Code Execution in Kestra via SQL Injection
CVE-2026-34612 https://www.cvedetails.com/cve/CVE-2026-34612/ OverviewCVE-2026-34612 là lỗ hổng SQL Injection dẫn tới RCE trong Kestra. Lỗ hổng ảnh hưởng tới Kestra v1.3.6 trở xuống, được vá từ v1.3.7 trở lên và v1.0.35. Endpoint bị ảnh hưởng chính là GET /api/v1/main/flows/searchBản chất của lỗ hổng là tham số filters[labels] trong API search flow được đưa xuống tầng respository sau đó key và value của label bị nối trực tiếp vào chuỗi SQL JSONB. Vì đoạn SQL này được truyền vào DSL.condition...
(VietNamese) Writeup CyberGame CTF 2026
Cybergame CTF 2026 Writeup CTF Time Event Link: https://cybergame.sk/ Writeup ORMT - ormt ORMT - ormt2 Background Chủ nhật, 01 Tháng ba 2026, 06:00 ICT — Chủ nhật, 10 Tháng năm 2026, 04:59 ICT Challenge ORMT - ormtTrang ChủKhi vào trang chủ, chúng ta sẽ được chuyển đến tới một ứng dụng sách với có chức năng search Find Your Book sau quá trình kiểm nghiệm ứng dụng thì không có gì đặc biệt Xem xét mã nguồn ứng dụngTrong thử thách, chúng ta có thể tải xuống mã nguồn và thực hiện phân tích ...
(English) Writeup THJCC CTF 2026
Challenge No Way Out Description Challenge: The janitor is fast, and the filter is lethal. You have 0.67 seconds to bypass the exit() trap before your existence is erased. Author: Auron Challenge Link: http://chal.thjcc.org:8080/ ListHomepage displays PHP codeLet’s delve into the source code and analyze this challenge in detail. First, let’s find out where the flag is located. We access the Dockerfile and we can see that the flag is written to the file /flag.txt 12345[....]COPY src/index.ph...
(VietNamese) VSL CTF 2026 Writeup (Author)
Trong cuộc thi VSL CTF 2026 năm nay, mình có đóng góp một số thử thách mảng Web. Mình rất vui khi VSL năm nay đã thu hút được hàng trăm đội đến từ khắp các miền trên Việt Nam. Đồng thời, mình cũng vô cùng tự hào khi team mình VSL.Sp33d_Of_T1m3 đã giành Quán quân bảng A và lọt Top 7 bảng B (toàn quốc).Tôi sẽ đi vào viết chi tiết 2 bài keygame và web easy easy Challenge Key Game Lý lịchHãy chơi nhạc đúng cách, đừng gian lận vì có hệ thống giám sát nghiêm ngặt.Link : http://124.197.22.141:7878...
(English) Cybersecurity Students Writeup 2025
In this cybersecurity student competition, our team made it to the finals of Group B, and below are the web challenges we solved, mainly web challenge sections. Challenge Leak ForceFirst, in the challenge, we’ll see a login page. Let’s create an account and log in. The HTTP history looks like this:As we can see, when logging in, it fetches a random /api/profile?id=1492 and returns a response with the user’s information: 1{"id":1492,"fullName":"solve 123",&...
(EngLish) CYBERCON DTU 2025 Writeup
These are the challenges I have researched and solved event CYBERCON CTF DTU 2025 Analyzing the challenge (WEB-URL-CHECKER)First, when you challenge the website, it will show you a URL link. Try entering a link like http://google.com, and it will return a status of 405 as shown below: First, let’s check where the flag is located. In entrypoint.sh, there’s a wp option add statement that inserts a row into the wp_options table (the table prefix in the script is wp_), so the ctf_flag content...







