Xss
Dojo #27
by YesWeHack
drag_indicator
drag_indicator
drag_indicator
WhazzUP - DOJO #27 (Until 07/10/2023)
How to submit your report
- Visit the DOJO program at https://yeswehack.com/programs/dojo
- Click on Submit report
- Login or create an account
- Submit your report
Win The Swag
Be Aware : This DOJO challenge must be active (see end date in the title)
The three best reports with a valid solution will win a swag pack. This is based on the following:
- Report quality
- That the solution is valid
- The submitted report contains all the necessary requirements (see section: GOAL)
Description
You used your full name for your newly created account and the developer of the website welcomes you by making your full name more noticeable to you. Nothing can go wrong with that!
Forget what I said, it's written in JavaScript.
Hint
~ Injection vulnerabilities that benefit from a normalization are clearly the best ones!
GOAL
BRUTE FORCE IS NOT ALLOWED!
The valid solutions for the challenge must meet these requirements:
- Exploit the Cross Site Scripting (XSS) vulnerability
- Include your XSS payload and a proof of concept of your solution in the report
drag_indicator
INPUT
OUTPUT
drag_indicator
drag_indicator