Using an XSS for Open Redirect

I recently got awarded some money for overcoming a fix to an open redirect by using an XSS. Here's how it worked:

Originally, there was an open redirect via the redirect_uri field. They fixed that one.

However, there was still an XSS possible that they hadn't fixed.

I wondered if I could still exploit this "resolved" bug...

The final payload looked something like this:
So, let's look at the payload:

When you decode from URL encoding:

The fromCharCode numbers decode to ""

The reason I had to do this is that double and single-quotes were being HTML-encoded in the source code reflected.

I couldn't do:

As this would get reflected as

Which, of course, this would not execute.

I thought about it for a while and realized I could try to construct a string using only ASCII values.

Originally I tried concatenating a string from a bunch of individual codes:

This payload did not execute. I believe I would have to encode the plus signs for this one to have worked, but before I got to try that, I discovered String.fromCharCode() allows for additional parameters past the first, so you could separate each ASCII value with a comma and pass an entire string in using only numbers if you find that single or double quotes are being filtered.

Even once I got the payload set up, it still wouldn't execute, as the javascript surrounding it in the source code for the page was causing a malformed statement.

To overcome this, I added a final forward-slash %2F at the end of the payload, turning the code that came after it into a comment, and causing the payload to execute.

There's several lessons to learn here:

  1. NEVER trust that a bug has been fixed. Always go back through old reports, especially if you are stuck and need inspiration.
  2. Sometimes, you need to step away from the computer for a while and do something else completely unrelated before you'll see something obvious.
  3. If you find an injection, and quotes+double-quotes are being filtered, try to work with only numbers.

If you would like individual mentoring on programming or hacking, please reach out to me on

Thank you for your time :)

