Self XSS in Create New Workspace Screen
Low
Vulnerability Details
Hi team,
I have found an vulnerability on your website .
step to reproduce :
1.firstly i want to say sorry for this .please read carefully
when im testing on your website .i was redirected to : https://customers.mattermost.com/cloud/connect-workspace
2.then navigate to create new workspace
3.on workspace name input this payload : "/><img src=x onerror=alert(document.cookie)>
4.xss will trigger
I know this domain is in out of scope ,but attacker can steal user cookies . I dont want any rewards for this i just want to aware you guys for this vulnerability .Hope you can understand .
Thanks for reading my report
## Impact
attacker can steal user cookies
Actions
View on HackerOneReport Stats
- Report ID: 1442017
- State: Closed
- Substate: resolved
- Upvotes: 40