Self XSS in Create New Workspace Screen
Low
M
Mattermost
Submitted None
Actions:
Reported by
unnamedx
Vulnerability Details
Technical details and impact analysis
Hi team,
I have found an vulnerability on your website .
step to reproduce :
1.firstly i want to say sorry for this .please read carefully
when im testing on your website .i was redirected to : https://customers.mattermost.com/cloud/connect-workspace
2.then navigate to create new workspace
3.on workspace name input this payload : "/><img src=x onerror=alert(document.cookie)>
4.xss will trigger
I know this domain is in out of scope ,but attacker can steal user cookies . I dont want any rewards for this i just want to aware you guys for this vulnerability .Hope you can understand .
Thanks for reading my report
## Impact
attacker can steal user cookies
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cross-site Scripting (XSS) - Generic