XSSy This lab is hosted on XSSy.
Visit the lab page to submit your payload.

Restricted Upload

I believe this lab is non-exploitable, but I am interested to see if someone can find a way. The objective is to call alert(document.cookie) and have the flag cookie appear.

The lab accepts file uploads, but blocks extensions known to be dangerous. Specifically:

Of course, security best practice is to use an allow list, not a deny list, serve user uploads from a separate domain, etc. This lab is about refining offensive techniques, not showcasing defensive best practice.

Upload a file: