"a stored xss issue in share post menu"
S
Slack
Submitted None
Actions:
Reported by
securitythinker
Vulnerability Details
Technical details and impact analysis
good day:
when a team mate named an xss payload:
ex: "><img src=x onerror=alert(1)>
"><img src=x onerror=alert(1)>
that xss payload will execute when making a post then share it, to a team that has an xss payload named. that shared as a direct message please see screenshot
when making post here:
https://hunter22.slack.com/files/create/space
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$500.00
Submitted
Weakness
Cross-site Scripting (XSS) - Generic