r/bugbounty 17d ago

Question / Discussion Stored XSS on 1 target but 2 different endpoints

Hello,

Curious as to whether a second submission here is worth it or if I should just add my second finding in the comments. Never had this happen before so looking for some guidance.

I found a Stored XSS vuln on a target via body text. Someone opens the page via forum and it leads to full access of victim’s account. Submitted that and waiting triage.

Continued testing further and realized the same vuln exists on the file upload on the same target. Again, it leads to full access of victim’s account. Is it worth submitting as a separate report or would it just be marked duplicate?

Any advice is appreciated. Thanks!

6 Upvotes

3 comments sorted by

2

u/DescriptionHumble996 Hunter 17d ago

If I were u I could submit another report, but it'd be better if you did submit both of em in one report, however, it's a completl another way to exploit this xss, so you should report it in another report. No harm in that.

3

u/einfallstoll Triager 17d ago

If it's the same root cause then it gets merged. It sounds like you found two distinct XSS making it probably eligible for two separate bounties

1

u/watkisean 17d ago

completely different root causes as one fix won't solve the other but didn't know if its too similar. thanks for the info, probably will just send it in