webPromedium
Lab 293 — CloudNest — Reflected XSS in Login Callback Label
hackadvisor
Task: Express.js workspace platform with admin bot URL review, reflected XSS in callback_label parameter on /login page. Solution: Injected autofocus/onfocus XSS payload via button breakout, used localhost:8080 to bypass X-XSS-Protection, exfiltrated admin flag via unauthenticated /api/support-tickets endpoint.
$ ls tags/ techniques/
nodejsxssexpresshoneypotadmin_botreflected_xssdecoy_flagsame_origin_exfiltrationautofocus_onfocuslocalhost_botcallback_label_injectionx_xss_protection_bypasshttponly_cookieno_csp
admin_bot_exploitationreflected_xss_exploitationsame_origin_data_exfiltrationautofocus_onfocus_xss_triggerlocalhost_url_discoverysupport_ticket_exfiltrationhoneypot_avoidancebutton_element_breakout
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Lab 408 — MailNest — Broken Authentication via Unauthenticated Password Reset— hackadvisor
- [web][Pro]Lab 113 — CloudNest— hackadvisor
- [web][Pro]Lab 328 — DataNest — NoSQL Operator Injection in Authentication— hackadvisor
- [web][Pro]Lab 75 — StayNest — Stored XSS in Hotel Booking Form— hackadvisor
- [web][Pro]Lab 153 — FlowDesk — CSRF Account Takeover via Email Change— hackadvisor