Intigriti's July XSS challenge - by @RootEval

Find a way to execute arbitrary javascript on this page and win Intigriti swag.

  • This challenge runs from July 26th until August 1st, 11:59 PM CET.
  • Out of all correct submissions, we will draw six winners on August 2nd:
    • Three randomly drawn correct submissions
    • Three best write-ups
  • Every winner gets a €50 swag voucher for our swag shop
  • The winners will be announced on our Twitter profile.
  • For every 100 likes, we'll add a tip to announcement tweet.
The solution...
  • Should work on the latest version of Chrome and FireFox both
  • Should execute alert(document.domain).
  • Should leverage a cross site scripting vulnerability on this domain.
  • Shouldn't be self-XSS or related to MiTM attacks
  • Should be reported at
By the way... Check your payloads right on Intigriti!

Now you can test your payloads and be sure they will not hurt anybody!

Your payloads: