notification-system

1 article
sort: new top best
clear filter
0 6/10

A researcher discovered a stored XSS vulnerability in a web application's internal notification system by injecting malicious HTML into a company name field. When users were invited to join the company, the unfiltered notification page executed the injected JavaScript payload for all invited users, demonstrating a critical vulnerability that a previous researcher had missed despite finding a related email injection issue.

Oleksandr Opanasiuk
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details