Loading HuntDB...

Stored Cross-Site Scripting found in custom integration app on https://admin.b360.autodesk.com.

Medium
A
Autodesk
Submitted None

Team Summary

Official summary from Autodesk

A stored cross-site scripting (XSS) vulnerability was found in Autodesk's Custom Integration feature on the admin panel at `admin.b360.autodesk.com`, which could have allowed an attacker to inject malicious JavaScript code when viewed by users. Autodesk has fixed the vulnerability and we thank @the-white-evil for reporting this issue.

Reported by the-white-evil

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cross-site Scripting (XSS) - Stored