shivamdixit/WebGoatPHP

the XSS 2 (Stored) does not reset after challenge is finished

Closed this issue · 0 comments

1.- zGo XSS 2 (Stored) challenge
2. Fill in a script in the message box such as <SCRIPT>alert(document.cookie);</SCRIPT>
3. Submit

Result
The user is not allow to go out of this challenge nor reset due to the"stored" xss.Everytime the XSS is been displayed. You need to delete the message XSS after the challenge is finished