Collected research
Inline Style Exfiltration: leaking data with chained CSS conditionals
CSS conditional functions inside a style attribute can test an element's own attribute value, and chaining them nested picks a different background image URL per candidate value. An attacker who controls only an inline style, with no stylesheet import and no selectors, can brute-force and exfiltrate short attribute data such as user identifiers.
Record
- Researcher
- Gareth Heyes
- Published by
- PortSwigger Research
- Date
- Topic
- Other
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Gareth Heyes, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .