Log in Join
[HIGH] · Self-hosted / private program · Accepted

Stored XSS ----- organization control Via an automatic invitation to the organization

Mohamed El-Fiky {Ghaziroot} Mohamed El-Fiky {Ghaziroot} Web application 26 Aug 2026

The affected asset is anonymised at the researcher's request.

Summary

A Stored Cross-Site Scripting (XSS) vulnerability was identified at ####. The injected script persists on the page and executes automatically in the browser of any authenticated user who visits the affected URL.

Although session cookies are protected with the HttpOnly flag and CSRF protection is in place, the XSS payload executes within the same origin, allowing it to read the CSRF token directly from the DOM and perform authenticated API requests on behalf of the victim — including sending admin-level organization invitations to attacker-controlled accounts.


found it with @z3rob