$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: Express.js knowledge base with WYSIWYG editor whose server-side sanitizer strips script tags and event handlers but allows iframe with srcdoc attribute. Solution: used iframe srcdoc with HTML-entity-encoded script tag to bypass sanitizer, exfiltrated admin's non-HttpOnly FLAG cookie via Interaction Server when admin bot reviewed the article.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar