Chained ExploitB-XSS -> ZipSlip -> Local File ReadA Cyber Apocalypse CTF 2022 web challenge chaining a blind XSS in an admin report-review page into a ZipSlip symlink attack on a firmware-upload endpoint to read /flag.txt off the server.#ctf#xss#zipslip#pythonMay 23, 2022 · 9 min read