Skip to content

fix(csp-low): escape reflected include, stop building live <script src> from it - #259

Closed
beanbeah wants to merge 1 commit into
OWASP-CTF:dc34-ctffrom
beanbeah:fix/csp-low-escape-reflected-include
Closed

beanbeah wants to merge 1 commit into
OWASP-CTF:dc34-ctffrom
beanbeah:fix/csp-low-escape-reflected-include

Conversation

@beanbeah

@beanbeah beanbeah commented Aug 9, 2026

Copy link
Copy Markdown

Isolated test: the CSP header restriction (script-src 'self') has been attempted before for csp-low, but the actual injection point — $_POST['include'] dropped straight into a hardcoded <script src='...'></script> — was never touched in any prior attempt for this level. Under a same-origin-only CSP that is still exploitable if the attacker can point the script src at anything same-origin (e.g. this module's own jsonp.php, or any other same-origin path).

This isolates just the vulnerabilities/csp/source/low.php fix: htmlspecialchars-escape the reflected value and stop wrapping it in a live <script> element, matching the shape both independent 55/55 reference solutions (#147, #155) use for this file.

Verified locally: header now Content-Security-Policy: script-src 'self';; submitting <script src="source/jsonp.php?callback=alert"></script> now renders as inert escaped text, not a live element.

…nclude value

The allow-list CSP header change alone (script-src 'self') was already
present on earlier attempts but the actual injection point was never
touched: the submitted 'include' POST value was still dropped straight
into a hardcoded <script src='...'></script> element. Under a 'self'-only
CSP that still lets an attacker point the src at anything same-origin
(e.g. this module's own jsonp.php, or any other same-origin path), which
the browser then fetches and executes - the header restriction did not
change that.

Matches the shape used by the two independent 55/55 reference solutions
(freituneir/DVWA#147, DeadPackets/DVWA#155): stop building a live script
element out of user input at all, and htmlspecialchars-escape the value
so it can only ever render as inert text.
@github-actions

github-actions Bot commented Aug 9, 2026 •

Copy link
Copy Markdown

🏆 DVWA — CTF Patch Score

░░░░░░░░░░░░░░░░░░░░  1 / 108 pts  (1%)

1 / 55 challenges patched

Per-challenge detail is withheld — it would reveal the rubric.

Commit: 84523bc · scoring run

🎉 Your result is on the leaderboard — see where you rank! 🏆

@beanbeah

beanbeah commented Aug 9, 2026

Copy link
Copy Markdown
Author

Closing as part of a full stand-down of this CTF push.

@beanbeah beanbeah closed this Aug 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant