Loading HuntDB...

XSS in gist integration

S
Slack
Submitted None
Reported by zemnmez

Vulnerability Details

Technical details and impact analysis

Cross-site Scripting (XSS) - Generic
1. Create a gist called: "><svg onload=alert(1)> 2. have gist integration enabled and put a link in a slack chat 3. Visit the 'raw' or 'new window' pages for this gist, for example: https://outpost.slack.com/files/zemnmez/F029MDY33/___svg_onload_alert_1__

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$500.00

Submitted

Weakness

Cross-site Scripting (XSS) - Generic