You can find all Client-side template injection XSS related Portswigger labs writeups.
Reflected XSS with AngularJS sandbox escape without strings
Reflected XSS with AngularJS sandbox escape and CSP
Last updated 1 year ago