DOM XSS in document.write sink using source location.search
document.write function, which writes data out to the page. The
document.write function is called with data from
location.search, which can be controlled using the website URL.
Reproduction and proof of concept
Enter a random alphanumeric string into the search box.
Right-click and inspect the element, and observe that your random string has been placed inside an
Break out of the