creator Intigriti's April XSS challenge
By kire_devs_hacks

Alert document.domain and win Intigriti swag.

  • This challenge runs from Monday the 8th of April until Monday the 15th of April, 11:59 PM UTC.
  • First blood will be rewarded with a €100 swag voucher! In addition to First blood, out of all correct submissions, we will draw six winners on Tuesday, the 16th of April:
    • Three randomly drawn correct submissions
    • Three best write-ups
  • Every winner gets a €50 swag voucher for our swag shop
  • The winners will be announced on our Twitter profile.
  • For every 100 likes, we'll add a tip to announcement tweet.
  • Join our Discord to discuss the challenge!
The solution...
  • Should leverage a cross site scripting vulnerability on this domain.
  • Should alert document.domain.
  • Shouldn't be self-XSS or related to MiTM attacks.
  • Should NOT use another challenge on the domain.
  • Should be reported at
  • Should require no user interaction.
Test your payloads down below and on the challenge page here!

Note: Some links may not work when clicked on this page, due to iFrame limitations - Please click the challenge link directly!

Note: We love unintended solutions, but if a clear oversight is found that significantly reduces effort to solve, we may patch it and reject your report in the name of fun!