macro

1 article
sort: new top best
clear filter
0 6/10

A stored XSS vulnerability was discovered in Zendesk's macro description field that could be exploited by bypassing the WAF by entering a benign value initially, then editing the field to insert the malicious payload after creation. The vulnerability was confirmed with an image onerror payload that triggered on the homepage.

Zendesk Hariharan S P5YCH0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 9 hours ago · details