Web Hack List

Collected research

Exploiting XSS in hidden inputs and meta tags

Uses the new popover onbeforetoggle and ontoggle events to execute JavaScript from normally inert hidden inputs and meta elements. Duplicate-ID targeting can reuse an existing popover control, reducing exploitation to a single injection point plus a user click.

Record

Published by
PortSwigger Research
Date

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of PortSwigger Research, first published at the original source. Preserved copies are kept so the citation survives its host.