BOOK THIS SPACE FOR AD
ARTICLE ADHello Guys, This is Another write-up after a long time. Delay for some personal issue
Let's Go along with it
The story begins with when I get the notification that I got a new private program invite on HackerOne. I open it and explore the website.
After a few minutes, I Request for Demo. I inject my always working payload in the first name ”><u>test{{7*7}} Then I went to sleep.
In the morning I checked my mail and guess what I saw, My payload was executed
In the above image, you can see the underline tag executed. I made the report and submitted it to the program. I am waiting for their response.
But the response is unexpected.