PortSwigger Web Security Academy: fingerprinting Twig from errors, reading the app’s own source through an exposed object, and chaining its methods into a custom exploit that reads and deletes files.
Server-Side Template Injection with a Custom Exploit




