Werkzeug
Suffers from known code execution vulnerability if Flask Debug is enabled
Console PIN Exploit
In some occasions the /console
endpoint is going to be protected by a pin. If you have a file traversal vulnerability, you can leak all the necessary info to generate that pin.
Find indepth information here.
Last updated