Rating:
Stealing state from a React component via XSS, see https://devcraft.io/2018/05/22/retter-rctf-2018.html for the writeup
I don't remember