You should check XSS Theory ๐ฃ
Testing Payloads
Check my note payloadbox XSS Payload List ๐ฅ
Scripts
- When performing an stored XSS, we have the following useful script (python2):
- Execute it
- Then we insert on the webpage the following XSS:
- Then we should get some session tokens like this (when someone clicks on it):