I am trying myself on an \'easy\' pentest box of HackTheBox. During my investigation I found an endpoint with a vulnerable variable example.php?file= that gets
example.php?file=