$ cat writeup.md…
$ cat writeup.md…
hackerlab
Task: a Flask museum site with registration, profiles, and an admin review bot hid the real attack surface behind a public user page. Solution: exploit stored XSS in profile_name, leak the bot pathname, enumerate /user/<id>, read /documents through the bot, recover admin credentials, and open /admin.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar