Can you spot the vulnerability? πŸ”Ž

Show us how you'd steal your victim's API key in the comments πŸ‘‡

The best explanation gets a 25€ SWAG voucher!🎫

@Intigriti Phishing link with modified icon parameter. Inject additional attributes into the link element as space is probably not disallowed by htmlspecialcharacters. Without reading the docs I don’t know what else
@Intigriti onload or another JS code attribute with a Beef hook probably
@phurd We've tried for quite a while to get JS attributes to work on link tags in the latest Chrome versions, but failed. Any chance you could provide a PoC of one that works?
There's something else here πŸ˜‰