File upload over private IM channel

Disclosed: 2016-07-13 23:56:39 By thisishrsh To slack
Unknown
Vulnerability Details
A team member can upload the files in the private IM chat channel of other members.This can be done by using the IM channel id. Please refer to the attached POC's. Let me know if any more details are needed.
Actions
View on HackerOne
Report Stats
  • Report ID: 143903
  • State: Closed
  • Substate: resolved
  • Upvotes: 5
Share this report