should we test for xss payload bypass in the bug bounty program ?
should we test for xss payload bypass in the bug bounty program ?