- Create a simple poll
- Set your User-Agent: or X-Forwarded-For: header to <img src="foo.jpg" onerror="alert('XSS')">
- Submit a vote
- From an electionadmin account, view the list of votes (Special:SecurePoll/list/xxx)
An alert will appear. Tested with SecurePoll version 3.0.0 (ab0903e), MediaWiki 1.37.0-alpha (e56ca63)