logo

DOJO CHALLENGE #18 Winners!

ID: 10411872-d5e3-59a8-b923-3fc19f9c691d

STIX ID: report--10411872-d5e3-59a8-b923-3fc19f9c691d

Feed Name: YesWeHack Blog

Threat Score
40/100

Date Published: 2022-02-11

Date Updated: 2026-07-15

...
...

This write-up documents a DOM-based XSS Web Application Firewall bypass demonstrated in a Dojo challenge: the author explains how template literal interpolation ($${{...}}) and an eval(atob(...)) payload bypass filters to inject JavaScript that alters a system.Allow array and triggers an in-page success alert, provides source code and a PoC, and recommends tightening WAF input restrictions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.