Stored XSS on Alibaba alicdn.com Via File Upload

Опубликовано: 10 Июнь 2026
на канале: Hamza Avvan (midnight)
3,207
135

Discovered stored xss vulnerability on Aliexpress Alibaba's alicdn was possible by uploading .html file while reviewing an order feedback. Tried to achieve RCE :( but the file itself gets downloaded due to Content-Disposition: attachment; header when uploading .php or anyother extension (.aspx, jsp etc) besides it was a cdn so never ever touched before.
Ethical hacking course

Status: Duplicate

#bugbounty #xss #ethicalhacking