Foreword
You discover blog garden header storage type XSS.
But think about it, since have applied for permission JS, can actually think Zuosha.
Payload
<img src=x onerror="prompt('had3s')">
You discover blog garden header storage type XSS.
But think about it, since have applied for permission JS, can actually think Zuosha.
<img src=x onerror="prompt('had3s')">