Operator sign-in
This web form is safe — it uses bound parameters. The same endpoint also answers a JSON authentication API used by the mobile app; that API is not on this page.
Reach the JSON API with an intercepting proxy: resend the sign-in as
Content-Type: application/json.
Stuck? You've missed the flag a few times. The full solution — root cause, exact payload and fix — is on the walkthrough page.
Check the solution on the walkthrough page →This is an isolated, intentionally-vulnerable sandbox. Data here is fake and scoped to you. The rest of CSPSHIVAM Playground is not part of the target.