CVE-2019-25263
MEDIUMZendesk App SweetHawk Survey 1.6 - Stored Cross-Site Scripting via Support Ticket Submission
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-25263. PoCs published by MTK.
AI-analyzed exploit summary This is a technical writeup describing a persistent XSS vulnerability in Zendesk App SweetHawk Survey up to version 1.6. The vulnerability allows attackers to inject malicious scripts into support tickets, which are then executed when users access the survey page.
Description
Zendesk SweetHawk Survey 1.6 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts through support ticket submissions. Attackers can insert XSS payloads like script tags into ticket text that automatically execute when survey pages are loaded by other users.
Exploits (1)
This is a technical writeup describing a persistent XSS vulnerability in Zendesk App SweetHawk Survey up to version 1.6. The vulnerability allows attackers to inject malicious scripts into support tickets, which are then executed when users access the survey page.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N