Baby Developer
Directory traversal in insecure Vitepress development server leads to information disclosure through SSRF
Description
Solution
@app.route('/flag')
def hello_world():
if request.remote_addr == dev and 'iPhone' not in request.headers.get('User-Agent'):
fp = open('/flag', 'r')
flag = fp.read()
return flag
else:
return "Nope.."Last updated