Hello everybody, today we have a simple Stored XSS vulnerability that leads to stealing cookies and Taking over the account. Let’s start Reconnaissance The target is only one single domain and its API subdomain let’s call them target.com and api.target.com , so simply when I do a pen-test for any target…