
Hello team, I am reporting another privilege escalation issue where a lowest privilege member(Support-Contributor) to full Support and Product administrator. Tested in Zendesk Enterprise(Sponsored) and Trial Account. From my past reports I was able to find privilege escalation issues on the endpoint /api/███ . The difference is, to perform a privilege escalation on the said endpoint, there should be at least one Product Admin privilege on the actor's account but this report does not require any Admin privilege(just the lowest privilege alone). Summary: The Contributor Role is the lowest Support role in Zendesk. In the UI alone, as a contributor, the accessible pages and and endpoints are very limited. With this role, the members page is not even accessible or restricted. With these restrictions, escalating your own role seem to be impossible. Improper Access Control to Privilege Escalation Vulnerable Endpoint: PUT /api███ HTTP/2 The /api████████ endpoint is used for API integration to █████. █████████ . However, the said endpoint does not validate the privilege of the user who is sending a request. With this bug, a member with even just the lowest privilege(Contributor) is able to escalate any members' privilege to FULL ADMINISTRATOR including its own privilege. Browsers Verified In: Latest version of Chrome and Firefox Exploit ```javascript //Exploit //get csrf token and id var xhttp = new XMLHttpRequest(); xhttp.onreadystatechange = function() { if (this.readyState...
SOCIAL SHARE CARD GENERATOR