Simple broken access control, Unicode normalization and bcrypt input truncation.
www.thesecuritywind.com/post/1753ctf...
Simple broken access control, Unicode normalization and bcrypt input truncation.
www.thesecuritywind.com/post/1753ctf...
There is a CSP in a meta tag.
Goal: get the content from the file hack.js and have it inserted in the page. like in the image
joaxcar.com/xss/self.html
There is a CSP in a meta tag.
Goal: get the content from the file hack.js and have it inserted in the page. like in the image
joaxcar.com/xss/self.html
www.thesecuritywind.com/post/world-w...
www.thesecuritywind.com/post/world-w...