Proving Impact Without Full Takeover - A Short XXS Story
Prelude Sometime during the last quarter of 2025, I led a web app pentest engagement for an internal application, and I stumbled across a reflected XXS vulnerability within a WYSIWYG editor used ...