Loading HuntDB...

Stealing app credentials by reflected xss on Lark Suite

Medium
L
Lark Technologies
Submitted None

Team Summary

Official summary from Lark Technologies

A reflected cross-site scripting (XSS) vulnerability was found on a Lark Suite endpoint via the 'next' parameter which an attacker could have potentially used to obtain app credentials (must first know the app ID). We have resolved this issue and thank @imran_nisar for reporting this to our team.

Reported by imran_nisar

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cross-site Scripting (XSS) - Reflected