Wednesday, 23 November 2016

Slack Stored XSS(Cross Site Scripting)

Slack Stored XSS(Cross Site Scripting)

Slack Stored XSS(Cross Site Scripting)


Hello Guys,

From a very long, I didn't`t write any blog post. :(

Well, Today we are going to see a Vulnerability in Slack Of Stored XSS(Cross Site Scripting) :)

One of the Slack URI - https://api.slack.com/apps/[appid]/general is not handling the user input properly, In a "name" parameter.

The input is getting reflected into the page without being properly sanitised or filtered, As a result it was possible for an attacker to Triager a Stored XSS Attack.

Interesting thing is that, This vulnerability can be exploited on other team and his member, As per this behaviour Slack Awarded $1000 for this vulnerability.


Full report can be found on hackerone - https://hackerone.com/reports/159460

Thanks,  Max Feldman for such fast response on my all reports.


POC is mention below.
Slack Stored XSS(Cross Site Scripting)




Slack Stored XSS(Cross Site Scripting)

POC Video 



Comments are always, Welcome.







6 comments:

  1. Unknown 10 February 2017 at 02:05

    Great Work bro :)

  2. Narendra Bhati 26 February 2017 at 11:28

    Thanks Bro :)

  3. Melinda Lamas 11 August 2017 at 04:03

    Nice Post, keep sharing like this.

  4. Narendra Bhati 22 August 2017 at 18:04

    Thanks you :)

  5. vikas 14 June 2018 at 10:47

    d

  6. ali 4 April 2020 at 21:46

    Nice Post, keep sharing like this.site

New comments are closed.