The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Lab: Exploiting DOM clobbering to enable XSS | something I don't understand

Eldawody | Last updated: Feb 19, 2023 10:37AM UTC

Hello, In this lab (https://portswigger.net/web-security/dom-based/dom-clobbering/lab-dom-xss-exploiting-dom-clobbering) payload used to solve it: <a id=defaultAvatar><a id=defaultAvatar name=avatar href="cid:&quot;onerror=alert(1)//"> why did we add `cib:****` to the payload? I tried to remove it, but the payload didn't work. is it a method to bypass characters encoding? Thanks

Ben, PortSwigger Agent | Last updated: Feb 20, 2023 03:18PM UTC