client-management

1 article
sort: new top best
clear filter
0 7/10

A researcher chained a self-XSS vulnerability with SMTP email injection to achieve stored XSS by crafting malformed emails via netcat that create new clients with XSS payloads in email fields, triggering when employees access client management pages.

Plenum Mailgun Medium
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details