Zum Hauptinhalt springen
Linux Tipps & HardeningDistribution Release: Besgnulinux 1.0 "Openbox"(04.10.2026 um 21:17 Uhr)
•••
Sichere ProgrammierungItch - to satisfy your nerdy adhd brain(04.10.2026 um 21:24 Uhr)
•
Sichere ProgrammierungHealtify: Turn your everyday bad habits into good one(04.10.2026 um 21:25 Uhr)
•••
Sichere ProgrammierungHow to write an AGENTS.md your AI agent actually follows(04.10.2026 um 21:26 Uhr)
•
Sichere ProgrammierungHow to Build a Voice AI Pipeline from Scratch(04.10.2026 um 21:26 Uhr)
•
Sichere ProgrammierungMy Mum Keeps Getting Scam Texts. I Built Her a Telegram Shield.(04.10.2026 um 21:26 Uhr)
•
Linux Tipps & HardeningDistribution Release: Besgnulinux 1.0 "Openbox"(04.10.2026 um 21:17 Uhr)
•••
Sichere ProgrammierungItch - to satisfy your nerdy adhd brain(04.10.2026 um 21:24 Uhr)
•
Sichere ProgrammierungHealtify: Turn your everyday bad habits into good one(04.10.2026 um 21:25 Uhr)
•••
Sichere ProgrammierungHow to write an AGENTS.md your AI agent actually follows(04.10.2026 um 21:26 Uhr)
•
Sichere ProgrammierungHow to Build a Voice AI Pipeline from Scratch(04.10.2026 um 21:26 Uhr)
•
Sichere ProgrammierungMy Mum Keeps Getting Scam Texts. I Built Her a Telegram Shield.(04.10.2026 um 21:26 Uhr)
•
Intelligence View
⚡ tsecurity.de Intelligence

Basecamp: Possible DOM XSS on app.hey.com

Summary: Hello Team, While testing it was observed that on https://app.hey.com/, on Search box there is a possibility of XSS. Although the payload is reflected…

Beitrag
0
Seite
0
↗ Quelle (vulners.com)
Social ReaktionenReagiere als Erste:r — dein Feedback zählt!

image
Summary: Hello Team, While testing it was observed that on https://app.hey.com/, on Search box there is a possibility of XSS. Although the payload is reflected in the DOM but the CSP blocks the execution of the script, the XSS can happen if the CSP is somehow bypassed. The Subject parameter is vulnerable. Apart from XSS, the HTML injection attack is working pretty straight forward. Steps To Reproduce: Go to https://app.hey.com Login to your account. Click on 'Write' Mail button. Add the recipient as yourself. In the Subject, add following payload TestPayload</a><a href="javascript:alert(1)">ClickHere</a> Send the mail. Go to top left corner Search Box and type "TestPayload" You will see the mail you sent to yourself, and tag will be there "ClickHere". Click on it, you will see the CSP violation in the Console. Below is the CSP of the page: script-src 'self' https://production.haystack-assets.com stats.hey.com *.braintreegateway.com *.braintree-api.com hcaptcha.com *.hcaptcha.com; object-src 'none'; base-uri 'none'; form-action 'self'; frame-ancestors 'none'; report-uri https://sentry.io/api/1371426/security/?sentry_key=3a5ea420eecc45bd9e1d1c2424683f3a&sentry_environment=production&sentry_release= As seen from the CSP, there might be a possibility of Host whitelists bypass. Impact If attacker send such type of mail to a victim and if victim accidentally searches for the same mail then the Script will be executed leading to account takeover. This is...
🔍 CTI & Forensik

Cyber Threat Intelligence & Forensik

ATT&CK-Navigator · IoC-Radar · Exploit-Belege
IoC Intelligence
1 Indikatoren · Defanged · STIX 2.1
3a5ea420eecc45bd9e1d1c2424683f3a
CTI Threat Relationship Graph
Akteure · Techniken · Beziehungen
2 Knoten · 1 Relationen
CVE / Incident Threat Actor Software MITRE ATT&CK CWE Weakness IoC
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Basecamp: Possible DOM XSS on app.hey.com

Thematisch verwandte Begriffe: Basecamp, Possible, appheycom · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

💬 Kommentare werden geladen…
Zum Aktualisieren ziehen
Nächster Beitrag