"I've won a bounty" generator

Medium Cross Site Scripting (XSS)

We know people love to say they've some bounties so simply input your username & bounty amount and then generate your image!

Can you discover how the application works and if there's anything interesting happening? Perhaps there is XSS somewhere hidden here.


Solution