Exploiting an LLM chatbot with prompt injection and XSS to leak system prompts, internal flags, and credentials.