The affected asset is anonymised at the researcher's request.
Writeup link: https://www.nyx0r.me/writeup/xss2cors-led-to-data-leakage
Summary
A reflected Cross-Site Scripting (XSS) vulnerability was discovered on a subdomain of a development-stage application, in a search feature used to query financial deals. While normally a standalone XSS is capped at medium severity, this instance was chained with a CORS misconfiguration on a separate page that exposed sensitive user data (emails, phone numbers, subscription plan info) to any origin considered "owned" by the app. Since the vulnerable subdomain qualified as a trusted asset under that CORS policy, the XSS could be used to silently fetch the sensitive data and exfiltrate it to an attacker-controlled server — escalating the bug from medium to critical severity.