Post cover image
Screenshot 2: the welcome-text field containing the entity-encoded <iframe> payload (admin panel).

June 28, 2026

Breaking the Same XSS Twice: Stored XSS in a Welcome Banner — Before and After the Fix

{وَأَنْ لَيْسَ لِلْإِنْسَانِ إِلَّا مَا سَعَىٰ ۝ وَأَنَّ سَعْيَهُ سَوْفَ يُرَىٰ}

By Hossam Hussein

5 min read