Stored xss in larksuite internal helpdesk and other user's helpdesk.
Medium
L
Lark Technologies
Submitted None
Team Summary
Official summary from Lark Technologies
A stored XSS (cross site scripting) vulnerability was found which an attacker could have potentially used to obtain access to the internal team's help desk and view submitted user tickets. We have resolved this issue and thank @imran_nisar for reporting this to our team.
Actions:
Reported by
imran_nisar
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cross-site Scripting (XSS) - Stored