@BugBountyHunt3r
BugBountyHunter.com 🪲
3 years
"Stored XSS on /manageappointment.php using the message parameter leading to account takeover" - disclosed by @holybugx , one of many great reports from our first hackevent! View all disclosed reports from the event ->
Tweet media one
1
40
197

Replies

@PPCVRJCUV
PPCVR ¦ 0x001
3 years
@BugBountyHunt3r @HolyBugx I think , it has HTTP request smuggling vulnerability too , just check it
0
0
0