Tags: securityfest javascript xss 2018 

Rating: 5.0

Write up here : http://thinkloveshare.blogspot.com/2018/06/writeup-securityfest-excess-ess-1.html

TL;DR -> In js, close a variable affectation, pop an iframe, use its alert function -> Profit !