customer-support

2 articles
sort: new top best
clear filter
0 8/10

A researcher discovered a blind XSS vulnerability in GoDaddy's internal customer support panel by injecting XSS payloads into user profile fields (first/last name), which executed when support agents accessed the CRM system. The vulnerability allowed arbitrary actions on customer accounts including domain transfers and account deletion, demonstrating how data poisoning can compromise backend systems drawing from shared data stores.

GoDaddy XSS Hunter Cobalt BeEF crm.int.godaddy.com sso.godaddy.com
thehackerblog.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details
0 1/10

A software engineer describes frustration with poor bug reporting processes at major companies, where non-technical support staff fail to properly escalate clearly identified bugs (OAuth callback errors, DOM rendering issues) to technical teams, resulting in unresolved issues despite multiple escalation attempts.

Fidelity Rocket Money
cupcake-unicorn · 1 day ago · details · hn