HGAME-2023-week2 Designer-复现
环境:NSSCTF
首页是一个注册界面,随便注册个名字进去
是个编辑按钮样式的界面,在这三个编辑框都尝试了XSS并没有反应,这时可以去审源码了
先看首页index.js的路由
1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798const express = require("express")const jwt = require("jsonwebtoken")const puppeteer = require('puppeteer')const querystring = require('node:querystring')const app = express()app.use( ...