Stored XSS in the user registration flow
mbmmgt.com
Injected payloads persisted through registration and executed on every subsequent dashboard load, giving any authenticated visitor a path to session theft and arbitrary in-origin actions.
Discovered in the user registration flow. Reported to the site owner and confirmed fixed.