Vulnerability hunting with Semmle QL: DOM XSS