A Flask application (login admin/admin) that stores a message per user and renders it unescaped. Its session cookie is not HttpOnly.
Not startedDockercommit 2f3e7d5x86_64 · aarch64Secret
Use a stored cross-site scripting payload to steal the session cookie and hijack the user's session.
The brief for this lab lives in its repository.