HACKR.GG
LabsSearchIt — Reflected XSS Cookie Theft
XSSEasy

SearchIt — Reflected XSS Cookie Theft

SearchIt reflects your query into the page with no escaping. Craft an XSS payload, send it to the bot endpoint, and steal the admin's session cookie.

// Machine control
Checking session...
// Submit flag