$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: DeskFlow support platform with CSP blocking JS and a sanitizer that strips <script> but allows <style>, plus an admin bot that reviews tickets. Solution: inject CSS into a ticket, use html:has(input[value^=...]) attribute selectors with cascaded custom properties to conditionally fire a same-origin background-image request to the platform's own reaction/activity-log endpoint, leaking the admin secret one hex character per auto-reviewed ticket — no JavaScript executed.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar