I made a website that gets your request path and returns it in a <link> tag like this:
<link rel="canonical" href="PATH_HERE">
You can go to any path you want and insert whatever you want in there, and the only the thing that gets sanitized are double quotes (").
The backend:
from flask import Flask
app = Flask(__name__)
# Catch every possible route
@app.route('/', defaults={'path': '/'})
@app.route('/<path:path>')
def catch_all(path):
path = path.replace('"', """)
return f"""
<head>
<title>Website</title>
<link rel="canonical" href="{path}">
</head>
"""
if __name__ == '__main__':
app.run(host="0.0.0.0", port=8080)
Here's the HTML returned when making a request to https://website.com/hello:
<html><head>
<title>Website</title>
<link rel="canonical" href="hello">
</head>
<body></body></html>
And here's the HTML returned when making a request to https://website.com/"</link><script>alert(1)</script>:
<html><head>
<title>Website</title>
<link rel="canonical" href=""</link><script>alert(1)</script>">
</head>
<body></body></html>
I'm wondering if it's even possible to make use of XSS in this website?