Redefining Impossible: XSS without arbitrary JavaScript
portswigger.net | research | #web-security | #xss | #side-channel | #exfiltration | #tagged-templates | #charset-restriction
Summary
Solving an 'impossible' XSS lab: with the payload confined to a single-quoted string and a tiny charset, Luan Herrera exfiltrates the cookie via side-channel techniques, not arbitrary JavaScript.
- Published
- Collected
Skip to content