Published onFebruary 6, 2025FlagYard - Web - GlidePath-TraversalSSTIWEBExploitationRCEFile-Upload-VulnerbilityExtract-VulnerbilityExploiting path traversal in a tar file extraction process to overwrite a rendered template, leading to Server-Side Template Injection (SSTI) and ultimately achieving Remote Code Execution (RCE)