Skip to main content

Exploiting clickjacking vulnerability to trigger DOM-based XSS

$ tldr PortSwigger · Clickjacking

Solve the lab

Resources by skill

Clickjacking · Cross-Site Scripting (XSS)

Comments & tips

Solved this lab a different way? Share it here — comments live in GitHub Discussions.
Last updated: 2026-05-08