email-injection

2 articles
sort: new top best
clear filter
0 6/10

A researcher discovered a stored XSS vulnerability in a web application's internal notification system by injecting malicious HTML into a company name field. When users were invited to join the company, the unfiltered notification page executed the injected JavaScript payload for all invited users, demonstrating a critical vulnerability that a previous researcher had missed despite finding a related email injection issue.

Oleksandr Opanasiuk
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details
0 7/10

A researcher chained a self-XSS vulnerability with SMTP email injection to achieve stored XSS by crafting malformed emails via netcat that create new clients with XSS payloads in email fields, triggering when employees access client management pages.

Plenum Mailgun Medium
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details