Link to the Google AMP formatted version of this blog post on IN-SCOPE CUSTOMER CONNECTED DOMAIN hubspot.modesite.net demonstrating Customer Portal "Image ALT text" setting Stored XSS vulnerability:
https://hubspot.modesite.net/blog/towncivilianwearehackerone.com?hs_amp=true