Reflected XSS into a JavaScript string with angle brackets HTML encoded.
href Attribute XSS Using javascript: URI Scheme Cross-Site Scripting (XSS) is often associated with injecting HTML tags or breaking out of script contexts, but a less obvious and equally dangerous variant occurs when user input is directly inserted into HTML attributes such as href . In particular, when applications fail to validate URL schemes, attackers can exploit the browser’s support for JavaScript URIs to execute arbitrary code. This technique is commonly referred to as attribute-based XSS via javascript: URLs . In a typical vulnerable application, user input is used to populate an anchor tag dynamically. For example: <a href="USER_INPUT">Click here</a> If the application does not properly validate the input before inserting it into the href attribute, an attacker can supply a malicious value such as: javascript:alert(1) When rendered by the browser, the HTML becomes: <a href="javascript:alert(1)">Click here</a> At first glance, thi...