October 9, 2026
Stored HTML Injection in Company-Generated Emails | My Bug Bounty Experience
Author: Mahafujul Haque Mehedi | New Bug Bounty Hunter

By Mahafujul Haque Mehedi
Stored HTML Injection in Company-Generated Emails | My Bug Bounty Experience
Hello everyone! I'm Mahafujul Haque Mehedi, a new bug bounty hunter passionate about web application security.
While hunting on a program through Bugcrowd, I tested the name field during account registration with an HTML injection payload.
Interestingly, I didn't receive an email immediately. After approximately 1–2 days, I received an email from the company and noticed that my injected HTML was reflected in its content.
What caught my attention was that the email came from the company's own email infrastructure. The application also required email verification to access the dashboard, raising questions about whether the vulnerable email workflow could be triggered before verification.
Improperly handled HTML in company-generated emails may create opportunities for email content manipulation and phishing, depending on the actual behavior and impact.
I reported the finding to Bugcrowd, hoping it would be a valid security issue. Unfortunately, the report was marked as a Duplicate. 🙂
Although it wasn't a unique finding, the experience taught me a valuable lesson: always investigate how applications store, process, and reuse user-controlled input—even when the impact appears much later.
Every duplicate is a learning opportunity. The next unique finding could be one test away! 🔍
#BugBounty #Bugcrowd #WebSecurity #HTMLInjection #CyberSecurity #EthicalHacking