Controlled security test

Compass cross-origin DOM XSS PoC

One click opens www.compass.com in a normal browser popup and sends the Userpilot iframeTrigger message from this separate origin. No privileged JavaScript is injected into Compass by this page.

Victim prerequisite: already signed in as an eligible Compass Agent/Staff/Specialist user with the Userpilot SDK loaded after functional consent.

Ready.

The payload only calls alert(document.domain). It does not read or transmit user data.