
Challenge 13/36: Stored XSS in Product Reviews - Cross-Site Attacks
ctfxsscross-site-scriptinginjectionsecurityweb-securitychallengeoopssec-store
Challenge 13/36 · Cross-Site Attacks. Stored XSS in product reviews. Easy · Injection · 30–45 min. Exploiting stored cross-site scripting in OopsSec Store's product review functionality to execute JavaScript in every visitor's browser. Spin up the lab: npx create-oss-store my-ctf-lab. See it on the roadmap at https://koadt.github.io/oss-oopssec-store/roadmap#challenge-13. Walkthrough available at https://koadt.github.io/oss-oopssec-store/posts/stored-xss-product-reviews (spoilers, read it once you are stuck). Star OopsSec Store on GitHub at https://github.com/kOaDT/oss-oopssec-store