cspshivam/playground
Redirect Level 5 / 6 Hard
← All labs

Fragment Token Leak

A freshly issued token rides along in the URL fragment. Redirect the flow so it spills onto your page.

CSPSHIVAM SSO — sign-in complete

After login, the SSO service redirects to your return URL and appends the freshly minted session token in the fragment (#access_token=…). Steal that token by choosing where the flow returns to.

This is an isolated, intentionally-vulnerable sandbox. Data here is fake and scoped to you. The rest of CSPSHIVAM Playground is not part of the target.