webeasy
Medium 1 - Script Src Attribute Breakout
spbctf
Task: XSS challenge where user input is inserted into script src attribute with only http/https prefix check. Solution: Break out of the src attribute using unescaped quotes to inject arbitrary HTML with XSS payload.
$ ls tags/ techniques/
attribute_breakoutscript_tag_injectionhtml_injection
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Create a free account with GitHub, then upgrade to Pro.
$ssh [email protected]