webeasy
Medium 2 - Regex Single Replacement Bypass
spbctf
Task: XSS challenge where escape function uses regex without /g flag, removing only the first match. Solution: Inject a sacrificial pattern that gets removed first, allowing the real XSS payload to remain and execute.
$ ls tags/ techniques/
regex_single_replacement_bypasssacrificial_pattern_injection
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Create a free account with GitHub, then upgrade to Pro.
$ssh [email protected]