Shazzer logo

Characters allowed to break double quotes

Chrome logo 1
Firefox logo 1
Edge logo 1

Characters allowed to break double quotes in the action attribute

p3n7a90n
Created byp3n7a90n
Created Jun 30, 2024
Updated May 27, 2025

Tweet
Detecting browser...
CategoryDOM Behavior
VisibilityPublic
TypeXSS
CharsetUTF-8
Template used:
<form id="test" action="aaa$[chr]onsubmit=alert(1)><input/type='submit'>0x0D
Code used after fuzz:
var form = document.getElementById("test");0x0D
if (typeof form.onsubmit === 'function') {0x0D
log(String.fromCharCode($[i]))0x0D
  }

Sample payloads

<form id="test" action="aaa0x00onsubmit=alert(1)><input/type='submit'>0x0D

Fuzz results

Chrome logo
Chrome 145.0.0.0 desktop Windows NT 10.0
Updated17 Feb 2026
Found 1 result
Loading...
Chrome logo
Chrome 144.0.0.0 desktop macOS 10.15.7older version
Updated17 Feb 2026
Found 1 result
Loading...
Firefox logo
Firefox 147.0 desktop Linux
Updated1 Feb 2026
Found 1 result
Loading...
Edge logo
Microsoft Edge 144.0.0.0 desktop Windows NT 10.0
Updated31 Jan 2026
Found 1 result
Loading...