We can manually inspect the JS source, or use the DOM invader to help locate our sinks as follow:

Here our sink is innerHTML, note that the innerHTML sink doesn’t accept script elements on any modern browser, nor will svg onload events fire. This means we will need to use alternative elements like img or iframe. Event handlers such as onload and onerror can be used in conjunction with these elements.

Luckily, the Exploit option of the DOM Invader comes with a predefined payload:

search="'><img src onerror=alert(1)>1'"<>

We can simply use this functionality and solve the lab.