Ask a Question
Ask Question Login
Corporate Training
  1. Community
  2. Cyber Security
  3. Question
Cyber Security

Can I use iframe XSS?

Asked by Amit Raj Mar 15, 2022 884 views 2 answers
Share

About this question

 I have a site, let's call it parent.com, that embeds a third party plugin from child.com in an iframe. I have found a XSS vulnerability on child.com.

The embedded page from child.com contains a form that POSTs to another page on the same domain. I can exploit the vulnerability by submitting the form. I intercept the POST request with Burp, and insert my payload into it. The payload is then executed.

My problem is that the payload runs inside the iframe on the child.com domain. My goal is to compromise parent.com (in order to win a bug bounty). Is it possible to use this vulnerability to accomplish that somehow? For example, can I somehow make the form submit to parent.com instead?

Your answer

2 Answers

Otis Hendricks Latest answer

Answered on Feb 3, 2026

The "sandbox" tag is unique to XSS iframes and specifies how the iframe's content space waves should be handled. You can fine-tune permissions to let an iframe communicate with the parent by using that tag. Although iframes are generally rather limited in their ability to influence a parent when loaded from a different domain, there may be case-specific ways to take advantage of them if you notice things like allow-same-origin, allow-scripts, allow-top-navigation, etc.

Was this helpful?

More Cyber Security discussions

Learn & Explore

Free tutorials and interview questions from industry experts — learn the skill, then get ready to prove it.

Latest Cyber Security Blogs

Guides, tips and career advice on Cyber Security from JanBask experts.