Collected research
User info extraction abusing placeholder injection in Zendesk
Zendesk expands placeholder expressions in ticket fields, including attributes of users copied on a ticket, and sanitises the subject but not the description. This write-up shows that a ticket created with no subject promotes the description into the subject and so escapes that sanitisation, and that the mandatory subject on web forms is sidestepped by opening the ticket by email, letting an attacker who CCs a victim extract their name, phone, role and custom fields.
Record
- Researcher
- Rikesh Baniya
- Published by
- Medium
- Date
- Topic
- Injection
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Rikesh Baniya, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .