Reflected XSS into attribute with angle brackets HTML-encoded – PortSwigger Write Up
Learn how to exploit a Reflected XSS in an HTML attribute in PortSwigger Lab. Step-by-step guide to inject a malicious attribute that executes JavaScript when angle brackets are HTML-encoded.