ClowderApp

Captured Data

Data exfiltrated via XSS callbacks.

Attack steps: submit XSS payload as feedback → visit /admin/reviews → the script fires and sends the admin cookie here.