Discovered stored xss vulnerability on Aliexpress Alibaba's alicdn was possible by uploading .html file while reviewing an order feedback. Tried to achieve RCE :( but the file itself gets downloaded due to Content-Disposition: attachment; header when uploading .php or anyother extension (.aspx, jsp etc) besides it was a cdn so never ever touched before.
Ethical hacking course
Status: Duplicate
#bugbounty #xss #ethicalhacking