Characters that can break out of an inline style background-image url
1
Characters that can break out of an inline style background-image url
Created by: 0xdef1ant
Created on: Saturday, July 13, 2024 at 9:12:51 PM
Updated on: Friday, December 6, 2024 at 9:56:28 PM
Vector type: XSS
Vector charset: UTF-8
Template used:
<div id="test" style="background-image: url($[chr];width:100%">hello</div>
Code used after fuzz:
let myDiv = document.getElementById("test");
function getCSSProperty(element, property) {
return window.getComputedStyle(element).getPropertyValue(property);
}
const width = getCSSProperty(myDiv, 'width');
if (width === '100%') {
log(String.fromCharCode($[i]))
}
Your browser was detected as:
Detecting... Detecting... Detecting... Detecting...
Sample payloads
<div id="test" style="background-image: url( ;width:100%">hello</div>
Fuzz results
Chrome 124.0.0.0 desktop macOS 10.15.7
Updated
Sat Jul 13 2024
Found 1 result
Loading...