0 / 12 XSS contexts fired this session. Each row is a different injection context - the goal is to notice how the payload has to change as the context changes. No flags: proof is calling /m03/api/solve/<key> from a payload that actually executed.
⬜ Reflected XSS - HTML body context (Search)
⬜ Reflected XSS - HTML attribute context (break out of value)
⬜ Reflected XSS - JavaScript string context (break out of quotes)