Xss

Dojo #27

drag_indicator
info
drag_indicator
inputs
drag_indicator
inspect

WhazzUP - DOJO #27 (Until 07/10/2023)

How to submit your report

  1. Visit the DOJO program at https://yeswehack.com/programs/dojo
  2. Click on Submit report
  3. Login or create an account
  4. Submit your report

Win The Swag

Be Aware : This DOJO challenge must be active (see end date in the title)

The three best reports with a valid solution will win a swag pack. This is based on the following:

  • Report quality
  • That the solution is valid
  • The submitted report contains all the necessary requirements (see section: GOAL)

Description

You used your full name for your newly created account and the developer of the website welcomes you by making your full name more noticeable to you. Nothing can go wrong with that!

Forget what I said, it's written in JavaScript.

Hint

~ Injection vulnerabilities that benefit from a normalization are clearly the best ones!

- - help

- - emergency-hint

GOAL

BRUTE FORCE IS NOT ALLOWED!

The valid solutions for the challenge must meet these requirements:

  • Exploit the Cross Site Scripting (XSS) vulnerability
  • Include your XSS payload and a proof of concept of your solution in the report
drag_indicator
waf
INPUT
OUTPUT
drag_indicator
code
drag_indicator
result