Collected research
Evading CSP with DOM-based dangling markup
Dangling markup normally dies under a strict CSP because no external resource may load. Injecting an unterminated base target attribute, or a form target, instead captures the following page markup into window.name, so a single victim click hands CSRF tokens and other secrets to an attacker page even under default-src 'none'.
Record
- Researcher
- Gareth Heyes
- Published by
- PortSwigger Research
- Date
- Topic
- XSS
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Gareth Heyes, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .