XSS
Easy · Reflected XSS

The Script Filter

HackerMart heard about the last finding and added a quick fix: they now strip the literal word `<script>` from search input. Most payloads are dead on arrival… but only the ones they thought of.

Objective

Fire an alert box even though `<script>` tags are stripped.

Target

HackerMart

Launch target

Submit flag