This is a reproduction of a XSS bug I found in the wild and successfully exploited to perform an account takeover. I discovered this while working on a private program so to the extent necessary I've minimized the content on this page to only that which is required.
Your challenge is to at a minimum pop an alert box, but bonus points for taking it a step further and importing a remote file that creates the alert. Although I had the advantage of being on the live site with all the content, everything you need (and everything I used) is on this page.