cross site scripting xss bugs in bug bounty