HACKTHEBOX CA26 Very-Easy WEB

Massagold

Stored XSS via unescaped EJS output, CSP bypassed using a Google JSONP endpoint, payload delivered to an admin bot that exfiltrated the flag from the admin inbox back to us.

#CyberApocalypse2026#Web#Very-Easy#Stored-XSS#CSP-Bypass