Back to CVEs & Disclosures
Rewarded

Reflected XSS — Public Program

Reflected cross-site scripting on a public bug bounty program, triaged and rewarded within hours of testing.

Status
Triaged · Rewarded
Reported
2025

Impact

  • Unsanitised query parameter reflected into the DOM without encoding.
  • Allowed session-context script execution against authenticated users.
  • Fixed by the vendor with output encoding and a stricter CSP.

Timeline

  1. Hour 0

    Payload confirmed on a production endpoint.

  2. Hour 2

    Report submitted with a reproducible PoC.

  3. Same day

    Triaged, rewarded and remediated.

View advisory on Github-advisories