HACKTHEBOX CA26 Very-Easy WEB

Massagold

Stored XSS via unescaped EJS output, CSP bypassed using a Google JSONP endpoint, payload delivered to an admin bot that exfiltrated the flag from the admin inbox back to us.

#CyberApocalypse2026#Web#Very-Easy#Stored-XSS#CSP-Bypass
HACKTHEBOX CA26 Very-Easy WEB

Gatery

An Elysia backend's signed session cookie fails to verify signatures (CVE-2025-66457), letting a forged session=inside cookie bypass auth.

#CyberApocalypse2026#Web#Very-Easy#CVE-2025-66457#Elysia