In this video I take you through the Whiterose room, which involves an SSTI vulnerability and sudoedit bypass to gain root access!
Sudoedit CVE: https://www.vicarius.io/vsociety/posts/cve-2023-22809-sudoedit-bypass-analysis
SSTI Link: https://eslam.io/posts/ejs-server-side-template-injection-rce/
Link to the room: https://tryhackme.com/r/room/whiterose
#penetrationtesting #tryhackme #ctf