[HIGH]
·
Self-hosted / private program
·
Accepted
The affected asset is anonymised at the researcher's request.
Summary
A Stored Cross-Site Scripting (XSS) vulnerability was identified at ####. The injected script persists on the page and executes automatically in the browser of any authenticated user who visits the affected URL.
Although session cookies are protected with the HttpOnly flag and CSRF protection is in place, the XSS payload executes within the same origin, allowing it to read the CSRF token directly from the DOM and perform authenticated API requests on behalf of the victim — including sending admin-level organization invitations to attacker-controlled accounts.
found it with @z3rob