Files
validator/OmCTF-2025/sploits/bashist

Sploit 1

Flagstore 1. Private posts (their content)

Vulnerability: A bug in code allows logging in as any user with password - password.

Fix: Add a $ sign before hashing the password in the api-user-register and api-user-login functions.

Sploit 2

Flagstore 2. Private posts (their content)

Vulnerability: An ineffective db-escape function and its absence in the db-list-user-posts function for user_token field.

Fix: Change the db-escape function to:

db-escape() {
    local str="$1"
    echo "${str//\'/\\\'}"
}