Personalised banner
The dashboard greets you with a banner personalised from your browser's User-Agent. The template
engine supports {{ expressions }}. There is no field to fill — the banner is built from a request
header.
Your banner
This text is rendered from your User-Agent header. Making the engine evaluate an expression means editing that header in the request.
Stuck? You've missed the flag a few times. The full solution — root cause, exact payload and fix — is on the walkthrough page.
Check the solution on the walkthrough page →This is an isolated, intentionally-vulnerable sandbox. Data here is fake and scoped to you. The rest of CSPSHIVAM Playground is not part of the target.