A Flask application (login admin/admin) that stores a message per user and renders it unescaped. Its session cookie is not HttpOnly.
Pas commencéDockercommit 2f3e7d5x86_64 · aarch64Secret
Use a stored cross-site scripting payload to steal the session cookie and hijack the user's session.
Le brief de ce lab se trouve dans son dépôt.