I found that you can exploit this vulnerability simply by adding an iframe `<iframe src="javascript:alert(document.domain)"</iframe>`