#TheFutureIsBright #BugBounty #bugbountytips Broken Crystals by https://brightsec.com
File Upload vulnerability chain with XSS.
There are 2 vulnerabilities
1. File upload vulnerabilities. The server do not check type of file with extraction.
2. Local file inclusion where attacker is able internal files
Lab: https://brokencrystals.com