Web Hack List

Collected research

User info extraction abusing placeholder injection in Zendesk

Zendesk expands placeholder expressions in ticket fields, including attributes of users copied on a ticket, and sanitises the subject but not the description. This write-up shows that a ticket created with no subject promotes the description into the subject and so escapes that sanitisation, and that the mandatory subject on web forms is sidestepped by opening the ticket by email, letting an attacker who CCs a victim extract their name, phone, role and custom fields.

Record

Researcher
Rikesh Baniya
Published by
Medium
Date
Topic
Injection

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Rikesh Baniya, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .