Post

Phantom Script

Phantom Script

SOLUTION

We can see at the bottom right of the web, they provide us some examples of XSS payload

By guessing, we combine 2 payloads then see what happend.

1
<img src=x onerror="alert(document.cookie)">