MEDIUM POSTS

Tale of XSS in Angular

Finding two reflected XSS vulnerabilities in an Angular application through automated subdomain monitoring and framework-aware testing.

Reading time1 min
Word count77
Case fileCASE_001

Angular XSS Featured Image
Angular XSS Featured Image

Hello Security Researchers and Hackers

In this writeup I explain how I found 2 rXSS vulnerabilities in Angular using automation.


Tools Used#

  • Findomain for subdomain monitoring
  • Wappalyzer for technology detection

Discovery Process#

  1. Received Telegram alert for new subdomains

  2. Identified Angular 1.6 using Wappalyzer

  3. Found reflected error parameter:

    https://redacted.com/Home/Error?error=USER_NOT_AUTHORIZED


Exploitation#

Used payload from PayloadsAllTheThings:

XSS Execution Proof
XSS Execution Proof


Key Takeaways#

  • Demonstrate concrete impact for better severity rating
  • Automate monitoring for fresh targets
  • Know framework-specific vulnerabilities
SickSecS3
ABOUT_THE_RESEARCHER()

SickSec

Security researcher and bug hunter focused on web security, APIs, GraphQL, OAuth, mobile flows, and the trust assumptions connecting them.

search.sh — archive index
SEARCHING /INDEX.JSONTYPE TO QUERY

Enter a vulnerability, technique, technology, or article title.