Xss
InnerHTML
by YesWeHack
drag_indicator
drag_indicator
drag_indicator
No script allowed
<script></script>
script tags do not work when added via innerHTML, can you find another way to trigger an XSS ?
Goal: alert(flag)
Hints
Solution
drag_indicator
INPUT
OUTPUT
drag_indicator
drag_indicator