Stored XSS (guestbook)

/stored · sink: Markup() / |safe

Comments are persisted and re-rendered as raw HTML for every visitor.


Comments

(no comments yet — be the first)

Hint

Submit a comment. It is stored in memory and rendered unescaped on every subsequent page load. Anyone who visits /stored/ after you executes whatever you put in.

View source for this lab → · /meta/stored