Summary by HubSpot
It was possible for a user to change their name to include HTML. When that user was deactivated, the deactivation email included the HTML in the user's name fields. The issue is fixed.
It was possible for a user to change their name to include HTML. When that user was deactivated, the deactivation email included the HTML in the user's name fields. The issue is fixed.
Thanks!
Can we disclose?!
events.hubspot.com
Other
Hello Gents,
app-eu1.hubspot.com
, I found out that users email could be injected with HTML tag via company name!Thanks and have a nice day!