Collected research
Go Go XSS Gadgets: Chaining a DOM Clobbering Exploit in the Wild
A reflected XSS on a sibling domain is used to postMessage into an auth portal whose listener writes attacker HTML through innerHTML; DOM clobbering of an undeclared global, via a named iframe holding an anchor, makes a static fragment served without CSP headers load an attacker-controlled script. The chain turns a permissive origin regex into script execution on the authenticated origin.
Record
- Researcher
- Brett Buerhaus, Sam Curry and Maik Robert
- Published by
- buer.haus
- Topic
- XSS
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Brett Buerhaus, Sam Curry and Maik Robert, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .