Craft

Would someone be able to point me to some good reading resources / provide a hint?
Got some credentials, am able to generate a token, know of a specific function that can be abused… but how…

*update - thanks for the people giving a nudge. finally cracked this box… definitely related to what kind of command you are using to get rce and the formatting of it…