Security research PoC - serialize-javascript deserialization execution. This page plays the role of the VICTIM website. All "victim" state is synthetic and is exfiltrated cross-origin to the researcher's separate ATTACKER site. Do not enter real credentials anywhere on this page.
Acme Dashboard
Victim page with realistic state. The payload sends everything to the attacker site configured below (one line - edit after upload if the attacker URL changes).