Account settings
You are viewing the victim's logged-in account. The "Update email" form below posts to this same endpoint. Your job: get that email changed without the victim ever submitting the form.
Signed in as
victim
Current email on file
victim@cspshivam.com
The application's real "Update email" form (for reference — this is what the app serves):
Attacker page — paste the HTML you would host on your own site. When you deliver it, the victim's browser (already logged in here) opens it.
Stuck? You've missed the flag a few times. The full solution — root cause, exact payload and fix — is on the walkthrough page.
Check the solution on the walkthrough page →This is an isolated, intentionally-vulnerable sandbox. Data here is fake and scoped to you. The rest of CSPSHIVAM Playground is not part of the target.