Trouble to Bypass a WAF/Filter for your XSS ?
You can send onxxxx=a
But can’t send onerror=a ?
You could try this little script I made to generate an Event Handlers Wordlist to bypass a Black List based Filter?
https://t.co/y7o61zt4Xb
#bugbountytips