Loading HuntDB...

Self XSS in Create New Workspace Screen

Low
M
Mattermost
Submitted None
Reported by unnamedx

Vulnerability Details

Technical details and impact analysis

Cross-site Scripting (XSS) - Generic
Hi team, I have found an vulnerability on your website . step to reproduce : 1.firstly i want to say sorry for this .please read carefully when im testing on your website .i was redirected to : https://customers.mattermost.com/cloud/connect-workspace 2.then navigate to create new workspace 3.on workspace name input this payload : "/><img src=x onerror=alert(document.cookie)> 4.xss will trigger I know this domain is in out of scope ,but attacker can steal user cookies . I dont want any rewards for this i just want to aware you guys for this vulnerability .Hope you can understand . Thanks for reading my report ## Impact attacker can steal user cookies

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cross-site Scripting (XSS) - Generic