Loading HuntDB...

Stored XSS in Macro Editing - Introduced by Admins to affect Admins

Medium
Z
Zendesk
Submitted None

Team Summary

Official summary from Zendesk

This issue was reported to us as a bypass to a previous fix by adjusting the payload. The cross-site scripting vulnerability can only be introduced by Support account administrators and only executes in a place where administrators within the account can access. We greatly appreciate the work and communication by @hariharan-s to help keep Zendesk secure!

Reported by hariharan-s

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cross-site Scripting (XSS) - Stored