Maintenance in progress: we are indexing a large batch of new skills. Some pages may load slowly or briefly show no results. Nothing is lost, and everything is back to normal within the hour.

Dangling Markup Injection

Dangling markup injection playbook. Use when HTML injection is possible but JavaScript execution is blocked (CSP, sanitizer strips event handlers, WAF blocks script tags) — exfiltrate CSRF tokens, session data, and page content by injecting unclosed HTML tags that capture subsequent page content.

ShulkwiSEC aa93622 13.3 KB Updated 21 repo stars

File contents

ShulkwiSEC/bb-huge/tree/main/skills/curated/dangling-markup-injection commit aa93622a44

Frequently asked questions

npx skillmds add shulkwisec/dangling-markup-injection