Introduction to Reflected DOM XSS

Reflected DOM-based Cross-Site Scripting (XSS) is a web security vulnerability where untrusted data is reflected into the DOM, allowing attackers to execute malicious scripts within a user’s browser. To mitigate XSS, web developers must ensure proper validation, sanitization of user input, and regular security assessments. Prioritizing web security and implementing robust measures can significantly reduce the risk of XSS vulnerabilities and safeguard users’ sensitive information.

Lab Solutions | Practical Work Time Reflected DOM XSS

This lab demonstrates a reflected DOM vulnerability. Reflected DOM vulnerabilities occur when the server-side application processes data from a request and echoes the data in the response. A script on the page then processes the reflected data in an unsafe way, ultimately writing it to a dangerous sink.
To solve this lab, create an injection that calls the alert() function.

Stepwise Solution of the lab:-

After accessing this lab you can see here we first noticed it has “Search” functionality.

To check its functionality let’s search random things. [NOTE: We will be using Burp Suite in this lab. So turn On intercept while searching Random words even end of the solving this lab]

So, here we are searching this to see it’s functionality and note that we are using Burp Suite on the other hand.

While searching as we mentioned the intercept is on. So, we’ve to forward the request.

In the site map there is a JSON response that uses an eval()function.

So we are good to go with the below payload, to see what will happen.


We successfully solved the lab.

