Exploits Explained Stored XSS in Email Fields: How a Plus Sign Became a Full Attack Vector
During a Synack engagement, an SRT researcher found that the email field's plus-sign subaddressing syntax let an XSS payload slip past client-side validation and store unencoded on an unauthenticated invitation page.


