Tags: web csp csrf prototype-pollution
Rating:
**tl;dr**
+ Prototype pollution in embedly to get attribute injection in iframes
+ CSRF using script tag that makes a request to the vulnerable endpoint
[https://blog.bi0s.in/2021/02/09/Web/BuildAbetterPanel-dice21/](https://blog.bi0s.in/2021/02/09/Web/BuildAbetterPanel-dice21/)