← All Labs
🛡 XSS INTERMEDIATE +80 XP · +35 no-hint bonus

Reflected XSS — SVG Sanitiser Bypass

ProfilePics renders user-supplied SVG as an avatar. The sanitiser strips <script> tags but leaves SVG event-handler attributes intact. Find a payload that fires.

https://bookshop.local/search