Cloudfront WAF can be bypassed for stored XSS using the payload ,. The WAF is blocking alert(), prompt(), confirm(), print(), and the content type is JSON, preventing the addition of double quotes.
