Stored XSS in Macro Editing - Introduced by Admins to affect Admins
Medium
Z
Zendesk
Submitted None
Team Summary
Official summary from Zendesk
This issue was reported to us as a bypass to a previous fix by adjusting the payload. The cross-site scripting vulnerability can only be introduced by Support account administrators and only executes in a place where administrators within the account can access. We greatly appreciate the work and communication by @hariharan-s to help keep Zendesk secure!
Actions:
Reported by
hariharan-s
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cross-site Scripting (XSS) - Stored