Acknowledged by BufferApp I was able to bypass their XSS filter and also found a issue with session cookies. For my responsible disclosure I got acknowledged. Share this:Tweet Share on WhatsApp (Opens in new window) WhatsApp Share on Telegram (Opens in new window) Telegram Print (Opens in new window) Print More Share on Reddit (Opens in new window) Reddit Share on Tumblr