Join
[CRITICAL] · Self-hosted / private program · Resolved

From Reflected XSS to Critical Bug Led to Sensitive Data Leakage

Abdelrahman Sayed Abdelrahman Sayed Web application 22 Sep 2026

The affected asset is anonymised at the researcher's request.

Writeup link: https://www.nyx0r.me/writeup/xss2cors-led-to-data-leakage

Summary

A reflected Cross-Site Scripting (XSS) vulnerability was discovered on a subdomain of a development-stage application, in a search feature used to query financial deals. While normally a standalone XSS is capped at medium severity, this instance was chained with a CORS misconfiguration on a separate page that exposed sensitive user data (emails, phone numbers, subscription plan info) to any origin considered "owned" by the app. Since the vulnerable subdomain qualified as a trusted asset under that CORS policy, the XSS could be used to silently fetch the sensitive data and exfiltrate it to an attacker-controlled server — escalating the bug from medium to critical severity.