Finding HTML Injection Vulnerability

Hello Everyone, I hope everyone is doing great. In this write-up I am going to explain how did I found a HTML Injection Vulnerability which got me a bounty of $150. Its a private website so lets say the website is www.redacted.com

The website allows to send group invitations as well as custom e-mails to send newsletters. The message body was vulnerable to HTML Injection.

Steps:

  1. Login to account
  2. Click on profile
  3. Go to emails
  4. Add Payload
  5. Click “Send Test Email”
HTML Injection

Leave a Reply

Your email address will not be published. Required fields are marked *

Achievements🏆

All the mentioned companies below, I have reported security vulnerabilities for which I have either received acknowledgement as Hall of Fame or received monetary reward as Bug Bounties. 

  • Telekom.
  • Sony.
  • Dell.
  • Adobe.
  • Frill.Co
  • Lenskart.
  • NCIIPC RVDP. (Goverment of India)
  • Magicpin.
  • Vercel.
  • YourDost.
  • Porche.
  • Channable.
  • OpenMoney.
  • Uizard.