At first glance, you'll start thinking that it will be some Java Template Injection challenges, and we have to bypass some certain filters and use native template syntax to inject a malicious payload into a template, which is then executed in the server-side...
Full writeup on : https://www.linkedin.com/pulse/wolverine-security-conference-ctf-seif-allah-homrani/?trackingId=3VLmeiEBTceyPEjSuqUNVQ%3D%3D

