Xss
HTML parser
by YesWeHack
drag_indicator
drag_indicator
drag_indicator
JS context
Does this protection is enough to protect you against XSS ?
spoiler: it's not
Goal: alert(flag)
Hints
Solution
drag_indicator
INPUT
OUTPUT
drag_indicator
drag_indicator