PEN-200 Web Application Attacks Practice Question
You are testing a Java web application that stores user-supplied SVG avatars. The application sanitizes SVG files by stripping `<script>` tags, then serves them from the same origin with `Content-Type: image/svg+xml`. When a victim views another user's profile, the browser renders the SVG inline. Which technique most reliably achieves script execution in the victim's session despite the sanitizer?
⚠ Common exam trap
The trap here is believing that removing `<script>` tags neutralizes SVG, when SMIL animation event handlers execute JavaScript without any script element.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the SVG `<animate>` element with an `onbegin` event handler that calls `alert(document.domain)` when the animation starts.
SVG is an XML format that supports SMIL animation and event attributes, so stripping only `<script>` leaves a large attack surface. Event handlers like `onbegin` on `<animate>` or `<set>` fire during rendering, executing attacker JavaScript in the victim's session on the same origin. This bypasses naive blacklist sanitizers that focus solely on script tags.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use the SVG `<animate>` element with an `onbegin` event handler that calls `alert(document.domain)` when the animation starts.
Why this is correct
SVG supports SMIL animation elements such as `<animate>` and `<set>`, which fire `onbegin` and `onend` events as soon as the document renders. Because the sanitizer only strips `<script>` tags, this event-handler vector survives and executes automatically when the victim views the profile, achieving same-origin script execution without interaction. This is a well-known SVG XSS bypass.
- ✗
Encode `<script>` as `<script>` so the sanitizer's regex fails to match the tag but the browser still parses it as script.
Why it's wrong here
HTML character references are not decoded inside tag names, so `<script>` is not parsed as a script element by browsers. The sanitizer's regex would also likely still match the literal `<scr` prefix if it is naive, but more importantly the browser will not execute it. This payload is a common misconception that does not produce execution.
- ✗
Embed a JavaScript URL in an SVG `<a xlink:href="javascript:alert(document.domain)">` element that the victim must click.
Why it's wrong here
Modern browsers block javascript: URLs in SVG anchor navigation, and the payload requires user interaction, which is unreliable for a proof-of-concept. The sanitizer also typically preserves anchor tags, so this is not a bypass of the filter so much as a fragile payload. It is a plausible but weak technique compared with event-handler-based execution that fires automatically on render.
- ✗
Insert an external `<image href="https://attacker.example/evil.svg">` reference that loads a second SVG containing the payload.
Why it's wrong here
Modern browsers block cross-origin SVG references from executing script in the embedding document, and the external resource is treated as an image, not an active document. Even if loaded, script inside a referenced SVG does not run in the parent origin. This approach also relies on the attacker controlling a separate host, which is unnecessary when inline event handlers already work.
About these practice questions
This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.