Dashboard

Welcome to RatXSS - a single-topic lab for CWAP Module 03: Cross-Site Scripting. Twelve sinks, twelve different injection contexts. The skill being drilled is context-aware payload construction: the same string is dangerous in one place and harmless in the next.

Where the bugs live

Proof-of-execution is self-contained: any payload that runs should call /m03/api/solve/<key>. There are no flag{...} values in this lab.