A9 Trusted Types bypass

TT-guarded sink:

Trusted Types is on (CSP require-trusted-types-for), so raw string -> innerHTML normally throws. But the app registered a default policy that returns the string unchanged, so the guard does nothing: ?q=<img src=x onerror=alert(document.domain)> still fires.


RatXSS Dojo · HackXpert Coaching · The XSS Rat · authorized lab use only