This lab has a stored XSS vulnerability in the comment functionality. Comments are rendered into the page for all users.
Objective: Post a comment that executes a script when the page loads. Capture the flag when the payload sticks.
How to solve this lab
- Click ACCESS THE LAB — the vulnerable app loads from lab.cyberlium.com inside this page (you stay on cyberlium.com).
- Follow the objective. Use the hint if you get stuck; open Solution guide only if needed.
- When you see a flag like CYBERLIUM{…}, copy it into Submit solution.
- Sign in first — correct flags add +90 XP to your account.
Practice app runs on the lab subdomain in the background — you never leave cyberlium.com. XP still goes to the same account.
Sign in first so XP is saved to your account.