Lab: DOM XSS in
document.write sink using source
location.search inside a select element
document.write function, which writes data out to the page. The
document.write function is called with data from
location.search which you can control using the website URL. The data is enclosed within a select element.
To solve this lab, perform a cross-site scripting attack that breaks out of the select element and calls the
storeIdparameter from the
location.searchsource. It then uses
document.writeto create a new option in the select element for the stock checker functionality.
storeIdquery parameter to the URL and enter a random alphanumeric string as its value. Request this modified URL.
- In the browser, notice that your random string is now listed as one of the options in the drop-down list.
Right-click and inspect the drop-down list to confirm that the value of your
storeIdparameter has been placed inside a select element.
Change the URL to include a suitable XSS payload inside the
storeIdparameter as follows: