← All findings
f-007 — Stored XSS in admin notes and support comments
medium · admin-panel + support-portal · status open · first seen 2026-04-23
Framework mapping
| Framework | Controls / requirements |
|---|---|
| ISO/IEC 27001:2022 ISMS |
A.8.28 |
| OWASP Top 10 (2021) Web |
A03:2021 |
| MITRE ATT&CK Adversary TTPs |
T1059.007 |