Mini-L-CTF-2022 minispringboot Thymeleaf模板注入 spel的绕过
就是一个低版本的Thymeleaf注入
漏洞点
public class MainController {
@GetMapping({
"/{language}"})
public String test(@PathVariable(name = "language") String language, @RequestParam(required = false) String name, Model model) {
if (name != null) {
model.addAttribute("name", name);