Photo Album image
DDC   DDC2025-NATIONALS   web  

Photo Album

awesome image awesome image

The source code shows an extension whitelist:
awesome image

The extension whitelist is however only on the extension, not the mime-type.
awesome image
Creating a tarfile with a symlink inside allows get-requests to the flag.
awesome image
voila:
awesome image