← All Labs
🛡 XSS INTERMEDIATE +70 XP · +30 no-hint bonus

Reflected XSS — Attribute Context

ProfileMe reflects your name into the `value` attribute of an input field. Angle brackets are escaped so a normal <img onerror> payload won't work. Find a way to break out anyway.

https://bookshop.local/search