Controlled security test
Compass cross-origin DOM XSS PoC
One click opens www.compass.com in a normal browser popup and sends the
Userpilot iframeTrigger message from this separate origin. No privileged
JavaScript is injected into Compass by this page.
Victim prerequisite: already signed in as an eligible Compass Agent/Staff/Specialist user with the Userpilot SDK loaded after functional consent.
Ready.
The payload only calls alert(document.domain). It does not read or transmit user data.