Stored XSS into HTML context with nothing encoded
PreviousReflected XSS into HTML context with nothing encodedNextDOM XSS in document.write sink using source location.search *
Last updated
Last updated
This lab contains a stored XSS vulnerability in the comment functionality. To solve this lab, submit a comment that calls the alert
function when the blog post is viewed.
Input the following into the "comment" text box on a blog post:
When you reload the blog post, you will be alerted.