DOM XSS and DOM Clobbering as Trust Problems

Lab HTML+JS page: location.hash into innerHTML, name=form clobber of a config object, harmless redacted payload, CSP as the fix.

April 14, 2021 · 6 min · 1203 words · Jose Adalberto Gutierrez Ochoa