postMessage → innerHTML XSS

Case memberhome-postmessage-dom-xss · unauthenticated · no CSP

Target:

The target page registers window.addEventListener("message", ...) with no origin check and writes e.data[0][i].questionContent straight into innerHTML. One click below opens the target and posts the payload to it.

The alert appears in the newly opened tab, showing that tab's own origin.

 

idle