Tags: web csp csrf prototype-pollution 

Rating:

**tl;dr**

+ Prototype pollution in embedly to get attribute injection in iframes
+ CSRF using script tag that makes a request to the vulnerable endpoint

[https://blog.bi0s.in/2021/02/09/Web/BuildAbetterPanel-dice21/](https://blog.bi0s.in/2021/02/09/Web/BuildAbetterPanel-dice21/)

Original writeup (https://blog.bi0s.in/2021/02/09/Web/BuildAbetterPanel-dice21/).