Clear it in 3 steps
-
Start the environment
-
Investigate the target
-
Submit the flag
This comment board is protected by a Content Security Policy restricting script execution to the site itself and a trusted CDN. Consider that content served from a "trusted" CDN is not automatically safe.
CSP is configured, but scripts from cdnjs.cloudflare.com are allowed
Consider using stored XSS to target the administrator's session information
A simulated admin bot periodically visits the page