Day 11 of Advent of Cyber, XSS — Merry XSSMas.
Hello everyone, its day 11 of AoC!!!!
Day 11 of Advent of Cyber, XSS — Merry XSSMas.
Hello everyone, its day 11 of AoC!!!!

Q1)Which type of XSS attack requires payloads to be persisted on the backend?
ans:- stored
Q2)What’s the reflected XSS flag?
Navigate to the website and in the search button, type this payload and hit search “<script>alert(‘Reflected Meow Meow’)</script>”
You will get a pop up, hit ok and then scroll down to the search bar and you will see something like this.

THM{Evil_Bunny}
Q3)What’s the stored XSS flag?
Scroll down to the send message section and type this payload “<script>alert(‘Stored Meow Meow’)</script>”
You will get a pop up, hit ok and then scroll down to the send message and you will see something like this.

THM{Evil_Stored_Egg}
“If this helped you, feel free to give it a clap!”
메타데이터
- post_id
- b0730df5d8a3
- slug
- day-11-of-advent-of-cyber-xss-merry-xssmas-b0730df5d8a3
- url
- https://medium.com/@pandasuhani3/day-11-of-advent-of-cyber-xss-merry-xssmas-b0730df5d8a3
- canonical_url
- https://medium.com/@pandasuhani3/day-11-of-advent-of-cyber-xss-merry-xssmas-b0730df5d8a3
- author_url
- https://medium.com/@pandasuhani3
- status
- ok
- fetched_at
- 2026-08-20 14:41:41