Find the context

context: unknown - find it

My Account

Signed in as you (CWAP trainee)
Search results for:
Filter: all · Sort: newest

Diagnostics (reflected request headers)

User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)
Referer: 
Accept-Language: 

Prove execution by making your injected JavaScript call /m03-p/api/solve/find-the-context (e.g. with fetch()). No external collector needed. This server-rendered sink also auto-marks once a value that would clearly run is reflected/stored here.

This panel takes many inputs (search, filters, profile fields, and it reflects a few request headers in the diagnostics box). Most of them are encoded correctly. Exactly one input, in one specific context, is not. Probe every input with a unique marker, watch where it appears in the response, and check which special characters survive intact. Then work out what that one context needs to break out - the payload that works for it will be inert everywhere else.