💩
DOM XSS executed — /#/search?q=%3Cimg%20src%3Dx%20onerror%3D%2…
headless
HIGH
🔍 Compromise path :
ENTRY POINT
DOM XSS (execution proven)
/#/search?q=%3Cimg%20src%3Dx%20onerror%3D%22document.title%3D%27XSSPWN66c6cef7%27%22%3E
→
UNLOCKED
Run code in the victim's browser
The attacker's code runs in the victim's page, with their privileges
→
UNLOCKED
Steal the victim's session
Token theft → full account takeover: act in their name, read their data, change their password
REQUEST
the injected code reads the session token (localStorage / non-HttpOnly cookie) and exfiltrates it
WHAT WE GET
the session token is reachable by the injected code in the browser
IMPACT
Token theft → full account takeover: act in their name, read their data, change their password
XSS → JavaScript execution on the victim's side → session theft and account takeover.
🧩 SSTI (template injection): nothing to report.
🔑 JWT (forgeable token): 1 confirmed.