0_CSP - Securinets-Quals 2023 Lu513n 2023-08-07 Web tl;dr CRLF Injection in Headed Key in Werkzeug headers.set Using CRLF Injection at /?user= to Get XSS at /helloworld Make the admin visit /?user=<PAYLOAD> and /helloworld using cache poison or bug in regex(uninteded) Read More Securinets-Quals CRLF XSS Cache-Poison