This lab contains a reflected cross-site scripting vulnerability in the search blog functionality where angle brackets are HTML-encoded. To solve this lab, perform a cross-site scripting attack that injects an attribute and calls the alert function.
Explore the application and understand it :
Basic understanding: Type of Application: Blogging Platform Users can add comments for the posts
search some random string


See source code of home page:

The
formcalls the GET/with parameter?search=<searchtext>
URL :
https://0ab2007e03ee13fd80ed03f400610053.web-security-academy.net/?search=somexyz123
See the source code after searching :

search text is inserted into the
valueattribute of<input>tag
So it can be possible to break out of the value attribute, lets test if the input is sanitized or encoded
search with special symbols :
some"xyz'123<abc>adsf


The special characters like
>and<are encoded but'and"are helping to break out of thevalueattribute
Payload planning:
Original code:
<input type=text placeholder='Search the blog...' name=search value="some">Break out of value attribute :
xyz"closes thevalueattribute"remained at the right end, it needs to be closed or ignored or commented
inject
onfocus="alert('XSS')-> with one double quotes"as opening statement and leave it empty on closing statement, since already the HTML document holds one double quotes"
<input type=text placeholder='Search the blog...' name=search value="some" autofocus onfocus="alert('XSS')">Payload:
xyz" autofocus onfocus="alert('XSS') 

The XSS is executed
See the source code now

The payload is injected as expected and got triggered on autofocus onfocus event (no user interaction)