2023-03-15 16:09:51 +00:00
id : addeventlistener-detect
info :
name : DOM EventListener - Cross-Site Scripting
author : yavolo,dwisiswant0
severity : info
description : EventListener contains a cross-site scripting vulnerability via the document object model (DOM). An attacker can execute arbitrary script which can then allow theft of cookie-based authentication credentials and launch of other attacks.
reference :
- https://portswigger.net/web-security/dom-based/controlling-the-web-message-source
classification :
cvss-metrics : CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
cvss-score : 7.2
cwe-id : CWE-79
2023-07-04 05:45:53 +00:00
metadata :
max-request : 1
2023-03-15 16:09:51 +00:00
tags : xss,misc
2023-04-27 04:28:59 +00:00
http :
2023-03-15 16:09:51 +00:00
- method : GET
path :
- "{{BaseURL}}"
matchers :
- type : regex
part : body
regex :
- (([\w\_]+)\.)?add[Ee]vent[Ll]istener\(["']?[\w\_]+["']? # Test cases: https://www.regextester.com/?fam=121118
2023-10-20 11:41:13 +00:00
# digest: 4a0a0047304502200dae342b4cead9ec9850751b8bd270a146f5bb324b5c97740c79e885e87a7671022100d6b9d433109287417ed460771846a6eec06dc37a26e48238e4d0a3508f338ec8:922c64590222798bb761d5b6d8e72950