Web Hack List

Collected research

Bypassing DOMPurify with good old XML

Uses differences between HTML and XML parsing to bypass DOMPurify in applications that sanitize markup before placing it in an XML-derived context. Processing instructions and CDATA handling let dangerous structure emerge after the sanitizer has approved the input.

Record

Researcher
RyotaK
Published by
GMO Flatt Security Research
Date

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of RyotaK, first published at the original source. Preserved copies are kept so the citation survives its host.