Hint for Waldo

@elio said:

@HeiGou said:
Anytips for the initial foot hold. I think it is an injection attack but I cant figure it out

Need help as well. I found some interesting things in the .js file and I’m able to use them but I’m not very good with java so I can’t understand how to exploit them.

I found Waldo in the background image though, so that’s a plus.

First is not Java, is JavaScript and second you don’t need to know anything about java or JavaScript to get anything.
You don’t even need the javascript files.
If you could use a proxy to see what is going when you add a new list or an item to the list…