> For the complete documentation index, see [llms.txt](https://sayonara.gitbook.io/writeups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://sayonara.gitbook.io/writeups/portswigger/xss/12-reflected-dom-xss.md).

# 12) Reflected DOM XSS

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FpJBzA91KKQBL3cLk7D0R%2Fimage.png?alt=media&amp;token=7ad8cbc3-5089-4828-a022-a5e1593c8798" alt=""><figcaption></figcaption></figure></div>

#### Locate possible injection points

As usual the first step is to analyse the application, we have a search functionnality so let's search for random string and then open the developer tools and find where the user input is located in the html

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FQUWcLYH2PyEmZLdLdcJc%2Fimage.png?alt=media&amp;token=0a165f24-aef7-4e6a-bf27-c55617ccdfdf" alt=""><figcaption></figcaption></figure></div>

looking at the debugger source shows an interestings javascript code that takes the user input and include it in the DOM

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FYqSVX6y7ZeuN9Z28iWCJ%2Fimage.png?alt=media&amp;token=183c6d46-0efc-4406-b750-b99ac43d68b6" alt=""><figcaption></figcaption></figure></div>

and we see that its using a dangerous sink which is eval

so to find xss we have to exploit the eval function

let's put the website in the scope in burp suite and search for something then go back to burp you will find an interesting endpoint that takes the user input search and returns a json where the results and the term being searched for

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2F2w5NKGADrLJwMr1nmFul%2Fimage.png?alt=media&amp;token=8938d19d-7dd1-47af-9dc1-0b297f23e63b" alt=""><figcaption></figcaption></figure></div>

so send this request to repeater

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FsKSWNOAr6hjmIgm4q7wn%2Fimage.png?alt=media&amp;token=ae5ddc4e-07e6-4f0f-a7f8-b7ca3116fd96" alt=""><figcaption></figcaption></figure></div>

now we have to escape the searchTerm to make the eval function execute js code for exemple alert() function

```
search=xxxx\"-alert(1)}//
```

* **`\"`** => escape the opening double-quotes character
* **`-`** => An arithmetic operator (in this case the subtraction operator) is then used to separate the expressions before the `alert()` function is called
* **`}//`** => a closing curly bracket and two forward slashes close the JSON object early and comment out what would have been the rest of the object

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FQwrSVTcJBgxgvZXxKYr4%2Fimage.png?alt=media&amp;token=621b2c24-c8a4-4855-9246-5ffb409ae368" alt=""><figcaption></figcaption></figure></div>

and now use it in the search and hopefully it will trigger an xss

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FujbItw4c7gUueMmUijZX%2Fimage.png?alt=media&amp;token=20aeb114-9143-4f76-93a0-6082b9bf7a8a" alt=""><figcaption></figcaption></figure></div>

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FHfhCJYhz6rm5wowYMocd%2Fimage.png?alt=media&amp;token=30e65748-a461-4e50-b973-ca4bb97b84c1" alt=""><figcaption></figcaption></figure></div>

and we have solved the lab

<div align="left"><figure><img src="https://1410593648-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYI2noEqPw69jd0hR7Prp%2Fuploads%2FAhtXOSc9Bl4SLM9rDlaN%2Fimage.png?alt=media&amp;token=35ca7743-54f9-4125-8fdf-172c9642336f" alt=""><figcaption></figcaption></figure></div>
