February 23, 2026
Belgian ethical hacking platform Intigriti hosted a new CTF (Capture The Flag) challenge in February 2026.
The challenge was build around a Self XSS with CSP bypass that could be converted in a Blind XSS to target the admin of the web application. The Blind XSS could be used to ex-filtrate the admin cookie.
Embedded writeup PDF: