OWASP / SecurityShepherd

Web and mobile application security training platform
https://owasp.org/www-project-security-shepherd/
GNU General Public License v3.0
1.33k stars 449 forks source link

Cross Site Scripting Lab 1 #779

Open jmanico opened 2 months ago

jmanico commented 2 months ago

under field training, the cross site scripting 1 lab does not accept this payload even though it pops the alert

<img src="https://placehold.co/600x400" onload="window.alert('test');" />

Thank you!

markdenihan commented 2 months ago

Huh, that's is a weird one. Onload isn't new!

On Thu 11 Jul 2024, 19:16 Jim Manico, @.***> wrote:

under field training, the cross site scripting 1 lab does not accept this payload even though it pops the alert

Thank you!

— Reply to this email directly, view it on GitHub https://github.com/OWASP/SecurityShepherd/issues/779, or unsubscribe https://github.com/notifications/unsubscribe-auth/AA2SVHXQ4JHSVTAPX5FDS53ZL3DYXAVCNFSM6AAAAABKXPX5MOVHI2DSMVQWIX3LMV43ASLTON2WKOZSGQYDGOBQGI2TOMY . You are receiving this because you are subscribed to this thread.Message ID: @.***>