Stored XSS into anchor href attribute with double quotes HTML-encoded – PortSwigger Write Up
Learn how to exploit a Stored XSS in the href attribute of an anchor in PortSwigger Lab. Step-by-step guide to execute JavaScript when clicking on the comment author's name when double quotes are HTML-encoded.