$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: Express/Node.js file sharing platform renders uploaded filenames via innerHTML without sanitization; admin bot reviews reported files. Solution: stored XSS via malicious filename with img onerror handler, exfiltrate admin's non-HttpOnly cookie by uploading a new file with stolen data encoded in the filename via FormData+fetch.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar