Enumeration Steps

This vulnerability can be found in email templates, blogs, forums, comments, wikis

***pay extra attention when evaluting these functionalities in a web application***

Basic Payload

${{7*7}}

${7*7}

<%= 7*7 %>

#{7*7}

*{{‘7’7}}

.{{7*7}}

If the application calculates the numbers, it means it is vulnerable

Flask Template Engine Commands

Reading Files