On this page
apsyleg1 min read
#portswigger #xss #template-literal #javascript #web-security
Reflected XSS in a Template Literal
Lab
Reflected XSS into a JavaScript template literal with angle brackets, single, double quotes, backslash and backticks Unicode-escaped · Practitioner
Reconnaissance
The search input string reflects into JavaScript code. Template literal syntax is used — injection via ${} is possible.
Exploitation
Final payload:
${alert(25)}
Lab solved.
More in this category
Arbitrary Object Injection in PHP (PortSwigger Lab)
Recovering leaked source code and injecting a serialized CustomTemplate object whose __destruct deletes an arbitrary file.
Using Application Functionality to Exploit Insecure Deserialization (PortSwigger Lab)
Tampering with the `avatar_link` field in the session object to delete an arbitrary file via the account-delete feature.
Modifying Serialized Data Types (PortSwigger Lab)
Abusing PHP loose comparison by changing the `access_token` type to integer `0` to bypass authentication.