HTML injection attack allows the injection of certain HTML tags. When an application does not properly handle user provided input, an attacker can supply valid HTML code via URL manipulation/modifying request and inject their own content into the page to plan severe attacks.
Reference Link - https://owasp.org/www-project-web-sec...