HTML Injection in email when deactivate a user

Disclosed by
x_bugcrowd
  • Engagement HubSpot
  • Disclosed date over 3 years ago
  • Reward $50
  • Priority P4 Bugcrowd's VRT priority rating
  • Status Resolved This vulnerability has been accepted and fixed
Summary by HubSpot

It was possible for a user to change their name to include HTML. When that user was deactivated, the deactivation email included the HTML in the user's name fields. The issue is fixed.

Summary by x_bugcrowd

Thanks!
Can we disclose?!

Report details
Activity