A Flask page built as an AngularJS 1.5 application. The submitted text is HTML-escaped by the server but lands inside the Angular template, which evaluates expressions.
Pas commencéDockercommit febaabcx86_64 · aarch64Secret
Get an AngularJS expression evaluated in the page and escape the sandbox to run JavaScript (client-side template injection).
Le brief de ce lab se trouve dans son dépôt.