PortSwigger

Description
Perform a reflected XSS attack that calls the alert function inside a JavaScript template string (template literal). All dangerous characters are escaped, but template literal interpolation ${...} still works.
Solution Steps
Step 1: Test with a random string
Enter a random alphanumeric string in the search box (e.g., # "\'<>;haha).

Step 2: Observe the Reflection
Using Burp Suite or DevTools, you’ll see your input reflected inside a JavaScript template string:

Step 3: Understand Template Literal Interpolation
In JavaScript template literals, ${...} allows you to embed expressions:
var name = "Thunder";
var greeting = `Hello ${name}!`; // "Hello Thunder!"
Step 4: Construct the Payload
Since ${...} executes JavaScript, you can simply put alert(1) inside it:
${alert(1)}
Step 5: Test the Exploit
-
Enter
${alert(1)}in the search box
-
Click “Search”

-
The alert fires immediately

-
The lab is solved
