The server strips <script>, then the client assigns the "clean" value to innerHTML. The re-parse mutates it - a mutation vector fires: <noscript><p title="</noscript><img src=x onerror=alert(document.domain)>">. Flag: flag{cwap_mutation_xss}.
CWAP Prep Labs · HackXpert Coaching · The XSS Rat · authorized lab use only