webeasy

Medium 1 - Script Src Attribute Breakout

spbctf

Task: XSS challenge where user input is inserted into script src attribute with only http/https prefix check. Solution: Break out of the src attribute using unescaped quotes to inject arbitrary HTML with XSS payload.

$ ls tags/ techniques/
attribute_breakoutscript_tag_injectionhtml_injection

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]