[BugBounty] Tips to Find Stored XSS

bigb0ss
InfoSec Write-ups
Published in
4 min readJun 8, 2022

--

Intro

Today, I would like to share some simple and quick ways to find stored XSS (Cross-site Scripting) vulnerabilities as well as 2 stored XSS vulnerabilities that I reported in HackerOne private programs.

For anyone who is new to AppSec or Bug Bounty, the stored XSS (aka persistent XSS) occurs when an application receives user-input data and save that data within the…

--

--

OSWE | OSCE | OSCP | CREST | Lead Offensive Security Engineer — All about Penetration Test, Red Team, Cloud Security, Web Application Security