Interested in going full-time bug bounty? Check out our blueprint!

DOM Purify Type Confusion by @slonser_

DOM Purify Type Confusion by @slonser_

How?

1. DOM Purify converts XML tags to HTML comment tags
2. Leaving the closing bracket empty, escapes to an HTML context allowing for onerror="alert(1)" and other fun stuff!