C
← Web Security Academy

Cross-site scripting (XSS)

Lab

Stored XSS via comment field

Apprentice+90 XP

This lab has a stored XSS vulnerability in the comment functionality. Comments are rendered into the page for all users.

Objective: Post a comment that executes a script when the page loads. Capture the flag when the payload sticks.

How to solve this lab

  1. Click ACCESS THE LAB to open the vulnerable practice app (stays on Cyberlium).
  2. Follow the objective. Use the hint if you get stuck; open Solution guide only if needed.
  3. When you see a flag like CYBERLIUM{…}, copy it into Submit solution.
  4. Sign in first — correct flags add +90 XP to your account.

Opens an intentional vulnerable app hosted on Cyberlium — you never leave this site.

Sign in first so XP is saved to your account.