←
juiceshop.local:3000HTTP 200 · reachable
24FLAWS
82ENDPOINTS
6ZONES
juiceshop.local:3000
🎯 ANALYSE
SCOPE — where to look
Whole site
One zone
INTENSITY — how far to go
Detectspots and confirms the flaws
Exploitreal impact · admin escalation · AI
PENTEST TYPE
Black
Grey
White
▸ Start exploitation
PROGRESS level reached
anon ✓→user→admin
82 entry points · 6 zones
💩

DOM XSS executed — /#/search?q=%3Cimg%20src%3Dx%20onerror%3D%2…

headless HIGH

🔍 Compromise path :

ENTRY POINT
DOM XSS (execution proven)
/#/search?q=%3Cimg%20src%3Dx%20onerror%3D%22document.title%3D%27XSSPWN66c6cef7%27%22%3E
→
UNLOCKED
Run code in the victim's browser

The attacker's code runs in the victim's page, with their privileges

→
UNLOCKED
Steal the victim's session

Token theft → full account takeover: act in their name, read their data, change their password

REQUEST
the injected code reads the session token (localStorage / non-HttpOnly cookie) and exfiltrates it
WHAT WE GET
the session token is reachable by the injected code in the browser
IMPACT
Token theft → full account takeover: act in their name, read their data, change their password
XSS → JavaScript execution on the victim's side → session theft and account takeover.
🧩 SSTI (template injection): nothing to report.
🔑 JWT (forgeable token): 1 confirmed.