Profile

context: stored profile fields, rendered in the member card

Member card

Display name: guest
About: New CWAP trainee.

Edit profile

Method: identify the exact context your input lands in, then craft the payload that breaks OUT of that context. Prove execution by making your injected JavaScript call /m03/api/solve/s_profile (e.g. with fetch()). No external collector needed. Server-rendered sinks also auto-mark once a value that would run is reflected/stored here.

The edit form escapes what it shows you, but the member card above renders your saved name and bio raw. Store a payload in a field, then let the card render it.