Self XSS in Create New Workspace Screen

Disclosed: 2022-02-20 09:08:08 By unnamedx To mattermost
Low
Vulnerability Details
Hi team, I have found an vulnerability on your website . step to reproduce : 1.firstly i want to say sorry for this .please read carefully when im testing on your website .i was redirected to : https://customers.mattermost.com/cloud/connect-workspace 2.then navigate to create new workspace 3.on workspace name input this payload : "/><img src=x onerror=alert(document.cookie)> 4.xss will trigger I know this domain is in out of scope ,but attacker can steal user cookies . I dont want any rewards for this i just want to aware you guys for this vulnerability .Hope you can understand . Thanks for reading my report ## Impact attacker can steal user cookies
Actions
View on HackerOne
Report Stats
  • Report ID: 1442017
  • State: Closed
  • Substate: resolved
  • Upvotes: 40
Share this report