Stored XSS in slack.com (integrations)

Disclosed: 2014-05-29 19:55:54 By jcamacho To slack
Unknown
Vulnerability Details
Hi Slack, i'm going to report stored xss in slack integrations. __Attack String (Payload):__ http://jeroldcamacho.com/%5Ex1s1s/slack.com.txt __Proof of Concept:__ [here is the video][Video]. [video]: https://www.dropbox.com/s/3qfo5fdezn6ci2q/slack.com%20xss.avi __Thanks,__ Jerold Camacho
Actions
View on HackerOne
Report Stats
  • Report ID: 10297
  • State: Closed
  • Substate: resolved
  • Upvotes: 1
Share this report