XXE is one of those things you never expect to be present but it somehow makes it way to a web chall.
Posts for: #Web
Inference Override 1
Log in to website using info leak in an internal route, and use query-parameter-injection to pollute locals.
BTW Always look at robots.txt :thumbs:.
Xss Xss
From Text injection to open redirect using javascript: pseudo protocol for unrestricted XSS.
First major web solve since picoCTF.
No Hack No CTF 2025
CTF Conducted by team Iced Tea.
Placed top 19, solved 5/7 pwn challenges, and one really good web challenge.