avatar
Gareth Heyes @garethheyes.co.uk

I discovered how to use CSS to steal attribute data without selectors and stylesheet imports! This means you can now exploit CSS injection via style attributes! Learn how below: portswigger.net/research/inl...

<div></div>
aug 26, 2025, 12:54 pm • 18 5

Replies

avatar
naugtur @naugtur.pl

wait, and what's stopping you from url(--val) ?

aug 26, 2025, 1:22 pm • 0 0 • view
avatar
Gareth Heyes @garethheyes.co.uk

You can't control the prefix or you need a style import

aug 26, 2025, 1:24 pm • 0 0 • view
avatar
Gareth Heyes @garethheyes.co.uk

PoC: portswigger-labs.net/inline-style... Custom Action: github.com/PortSwigger/...

Video thumbnail
aug 26, 2025, 12:54 pm • 3 0 • view