I found one stored xss which is in cart details I am unable to escalate the issue because
The payload is stored in cart details but those can only view by me so how could we steal cookies of other users ?
The organization considered it as self xss. someone please help me to understand what can be the highest impact of it.