
This report details exploiting Trickster via an XSS in PrestaShop (CVE-2024-34716) to gain www-data access, extracting database credentials for SSH as james. A root shell in Docker is obtained via ChangeDetection.io (CVE-2024-32651), revealing adam’s credentials, followed by root escalation with CVE-2023-47268 in PrusaSlicer.
Trickster is a medium-difficulty Linux machine featuring multiple vulnerabilities across different services. This report outlines the process of exploiting these vulnerabilities to achieve full system compromise.
Exploiting PrestaShop (CVE-2024-34716)
www-data user.Extracting Database Credentials
james, enabling SSH access.Exploiting ChangeDetection.io (CVE-2024-32651)
Extracting User Credentials from Backups
adam.adam.Privilege Escalation via PrusaSlicer (CVE-2023-47268)
By chaining together multiple vulnerabilities—XSS in PrestaShop, SSTI in ChangeDetection.io, and privilege escalation in PrusaSlicer—we achieve full system control over the Trickster machine.