Welcome.aspx RedirectUrl → window.location XSS

Case platform1landing-welcome-dom-xss · unauthenticated · no CSP

Target:
https://admin.membersmarkfans.com/Platform1Landing/Pages/Landing/Welcome.aspx?Action=DoExternalPanel

RedirectUrl is a hidden field the server echoes straight back from the POST body with no scheme validation. The page's own script then runs window.location = document.getElementById("RedirectUrl").value, so a javascript: value executes in the target's origin.

It has to be a POST — on a plain GET the field renders with no value, so the sink is empty. That is why this one cannot be a clickable link.

The ASP.NET tokens below were harvested from the live page and are embedded statically, so no token-fetching step is needed. If the app is redeployed they may stop matching; re-harvest with a GET of the target URL and swap the three values.

Payload (goes into RedirectUrl):

 opens a new tab

idle