If you came across websites use dotcms make sure to check those 2 bugs
1 : rxss
https://t.co/1ySlM5SrjE
Thanks @brutelogic for bypass waf );
2: broken auth leads to full system users,emails,privlgs
1: visit https://t.co/LqDCpIqNjK
2: go to https://t.co/f1yN3hAxwN
#bugbountytips