This lab contains a DOM-clobbering vulnerability. The comment functionality allows “safe” HTML.

To solve this lab, construct an HTML injection that clobbers a variable and uses XSS to call the alert() function.

https://portswigger.net