The Lab
Here is how PortSwigger describes it
This lab contains a stored cross-site scripting vulnerability in the comment functionality. To solve this lab, submit a comment that calls the alert function when the blog post is viewed.
Previously we did reflected XSS into HTML context, now we will be dealing with stored XSS
Reflected vs Stored#
The two aren't as different as they sound, the payload and the flaw behind them are basically the same thing, the only thing that changes is where the input goes before it comes back
With reflected XSS, our input never leaves the request-response cycle. We send it in the URL, the server drops it straight into the response, and it's gone the moment that response is done. Anyone we want to hit needs to click a link we crafted.
With stored XSS, our input gets written to the database first. Submit a comment once, and it sits there permanently. From that point on, every single visitor who loads that page gets served our payload straight out of storage, no crafted link required, no interaction needed beyond just viewing the page. That's what makes stored XSS the more dangerous of the two
Looking at the Lab#
This time we don't see any search functionality on the index page, but we do see a few posts listed there, so let's check one out.
Upon accessing a post, we see a new piece of functionality, a comment section, which allows a user to leave a comment under the post.
Step 1 - Identify the Injection Point#
The comment box is our injection point here. There's a name, an email, a website field, and the comment body itself, and it all gets rendered back out on the page once submitted, under the post, for anyone who loads it afterwards.
Step 2 - Submit the Payload#
Since we already know this reflects our input straight into the HTML body with no encoding involved, we don't need anything fancy here either. We'll go with the same payload we used in the reflected lab.
htmlCopy
<script>alert(1)</script>
Fill it into the comment box and hit post comment. That's it, there's no second step. The moment the comment gets rendered back onto the page, our <script> tag executes and the alert(1) popup fires.
With this, the lab is solved!
