Defenses: Input is placed inside an HTML attribute value (double-quoted). No tag filtering.
Your input is reflected into an input element's value attribute.
Reflected element: