$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: HelpWave support platform allows rich HTML/SVG in ticket descriptions, run through a custom sanitizer; an automated agent bot reviews tickets (stored XSS, cookie theft). Solution: the sanitizer strips standard event handlers but misses SVG SMIL animation handlers (onbegin/onend on animate/set), giving stored XSS that fires on the agent; exfiltrate the non-HttpOnly secret_token cookie via the same-origin replies API back into the ticket thread.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar