Stored Cross-Site Scripting found in custom integration app on https://admin.b360.autodesk.com.
Medium
A
Autodesk
Submitted None
Team Summary
Official summary from Autodesk
A stored cross-site scripting (XSS) vulnerability was found in Autodesk's Custom Integration feature on the admin panel at `admin.b360.autodesk.com`, which could have allowed an attacker to inject malicious JavaScript code when viewed by users. Autodesk has fixed the vulnerability and we thank @the-white-evil for reporting this issue.
Actions:
Reported by
the-white-evil
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cross-site Scripting (XSS) - Stored