#TheFutureIsBright #BugBounty #bugbountytips BrokenCrystals by https://brightsec.com
Reflect XSS on testimonial entry point in search query.
After request it with query in, the response returns injected string with Content-Type: text/html. It means there we have reflected XSS without filtering dangerous characters.