- Published on
- Name
- rvr
Hacking a note-taking app from BITSCTF 2025. The exploit leverages a UTF-8 to ASCII conversion issue to inject XSS that remains unnoticed by DOMPurify and uses angular.js from Cloudflare CDN to bypass CSP restrictions.
Security enthusiast who enjoys understanding how things work. Specializes primarily in web category.
Flags
89
Writeups
3