notifications

1 article
sort: new top best
clear filter
0 5/10

A researcher discovered a stored XSS vulnerability in a web application's internal notification system by injecting HTML/SVG payloads into company names during user invitation functionality, which were then reflected without sanitization when users viewed invitation notifications.

Oleksandr Opanasiuk
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 10 hours ago · details