$ cat writeup.md…
$ cat writeup.md…
hackerlab
Task: a Flask/Werkzeug publication page reflected the search parameter into HTML and exposed a same-origin report feature. Solution: inject JavaScript through reflected XSS, submit the crafted local URL to the admin bot, and exfiltrate the flag from document.cookie to Webhook.site.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar