Reflected XSS — Public Program
Reflected cross-site scripting on a public bug bounty program, triaged and rewarded within hours of testing.
- Status
- Triaged · Rewarded
- Reported
- 2025
Impact
- Unsanitised query parameter reflected into the DOM without encoding.
- Allowed session-context script execution against authenticated users.
- Fixed by the vendor with output encoding and a stricter CSP.
Timeline
Hour 0
Payload confirmed on a production endpoint.
Hour 2
Report submitted with a reproducible PoC.
Same day
Triaged, rewarded and remediated.