Jarvis

I am stuck on the initial foothold:

I found:
Cookie Without H*** O*** Flag
p**MA*** CSRF
Tw * g Server Side Template Injection

but still stuck. any tips?