xss-vulnerability

2 articles
sort: new top best
clear filter
0 6/10

A stored XSS vulnerability was discovered in Zendesk's macro feature by exploiting the macro description field, coupled with a WAF bypass technique that involves submitting benign content initially and injecting the payload during subsequent edits when WAF validation is less stringent.

Zendesk Hariharan S P5YCH0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 12 hours ago · details
0 5/10

A researcher demonstrates chaining a CSRF vulnerability with a stored XSS flaw to achieve persistent XSS execution. By exploiting a missing CSRF token on a template creation endpoint and leveraging an HTML/SVG injection point in a description field, an attacker can create a malicious template that executes JavaScript when viewed by any user.

Mohamed Sayed
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 12 hours ago · details