siunam's Website

My personal website

Home Writeups Research Blog Projects About

Stored XSS into HTML context with nothing encoded | Dec 29, 2022


Welcome to my another writeup! In this Portswigger Labs lab, you'll learn: Stored XSS into HTML context with nothing encoded! Without further ado, let's dive in.


This lab contains a stored cross-site scripting vulnerability in the comment functionality.

To solve this lab, submit a comment that calls the alert function when the blog post is viewed.


Home page:

In the home page, we can view other posts:

And we can leave a comment:

Let's try to injection some HTML code in the comment field:

As you can see, our input became a real HTML tag!

<section class="comment">
    <img src="/resources/images/avatarDefault.svg" class="avatar">                            test | 29 December 2022

Now, try to injection a JavaScript function called alert():


Now whoever view this post, they will trigger our alert() JavaScript function, as our comment has been stored to the web application's database!

What we've learned:

  1. Stored XSS into HTML context with nothing encoded