webeasy

Medium 2 - Regex Single Replacement Bypass

spbctf

Task: XSS challenge where escape function uses regex without /g flag, removing only the first match. Solution: Inject a sacrificial pattern that gets removed first, allowing the real XSS payload to remain and execute.

$ ls tags/ techniques/
regex_single_replacement_bypasssacrificial_pattern_injection

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]