C
← Web Security Academy

Cross-site scripting (XSS)

Lab

DOM XSS via document.write

Practitioner+120 XP

This lab uses document.write (simulated) with a URL parameter. The sink is entirely client-side.

Objective: Craft a URL fragment/query that causes script execution through the DOM sink.

How to solve this lab

  1. Click ACCESS THE LAB to open the vulnerable practice app (stays on Cyberlium).
  2. Follow the objective. Use the hint if you get stuck; open Solution guide only if needed.
  3. When you see a flag like CYBERLIUM{…}, copy it into Submit solution.
  4. Sign in first — correct flags add +120 XP to your account.

Opens an intentional vulnerable app hosted on Cyberlium — you never leave this site.

Sign in first so XP is saved to your account.