postMessage() III

This exercise covers how insecure calls to the JavaScript function postMessage() can be used to trigger a Cross-Site Scripting

medium diffculty Medium difficulty
average completion time icon
Between 1 and 2 hours average completion time
number of users completed icon
823 users completed this exercise


Make sure you check out PentesterLab PRO and PentesterLab PRO Enterprise to develop your skills.