Instruction

This lab contains a simple reflected cross-site scripting vulnerability in the search functionality. To solve the lab, perform a cross-site scripting attack that calls the alert function.

Solution

  1. Try to search some keyword using search form
  2. Notice the url changed to https://0a5f00c503561fcf843f90e5009d00cb.web-security-academy.net/?search=mysearchword
  3. Try to search again using value <script>alert('hello')</script> and search
  4. The url will changed like this and the alert will showed up https://0a5f00c503561fcf843f90e5009d00cb.web-security-academy.net/?search=%3Cscript%3Ealert(%27hello%27)%3C/script%3E
  5. solved