ForBugHunters
Photo
click to show
click to show
Stored XSS ➜ $$$ 💰
Found a Stored XSS in the team creation flow.
Steps:
1. Create a new team.
2. Set the team name to:
"><script>alert(document.cookie)</script>
3. Enable the option requiring all team members to use 2FA.
4. Join the same team with another user.
Result:
The second user receives a message prompting them to enable 2FA in (Team Name). Since the team name is rendered without proper sanitization, the injected JavaScript executes, resulting in a Stored XSS.
Status: ✅ Fixed & Rewarded.
Linkedin : https://www.linkedin.com/posts/ayman-amer1_bugbounty-storedxss-xss-activity-7479481896792608768-NSxY
8 · 5K ·