Acme Dashboard

Role: VICTIM website. This domain plays the vulnerable web application in the serialize-javascript proof of concept (Intigriti report evidence). The pages below embed serialized output produced by serialize-javascript@7.1.2 from a spoofed toString() function; the payload executes when the browser parses the output.

Security research PoC. All "victim" state is synthetic (demo session cookie, fake JWT, fake CSRF token) and is exfiltrated cross-origin to the researcher's separate ATTACKER site. Do not enter real credentials anywhere on this domain.

Pages