HTML Injection in email when deactivate a user

Disclosed by
mega7's avatar
mega7
  • Engagement HubSpot
  • Disclosed date over 2 years ago
  • Reward $50
  • Priority P4 Bugcrowd's VRT priority rating
  • Status Resolved This vulnerability has been accepted and fixed
Summary by HubSpot

It was possible for a user to change their name to include HTML. When that user was deactivated, the deactivation email included the HTML in the user's name fields. The issue is fixed.

Summary by mega7

Thanks!
Can we disclose?!

Report details
Activity
  1. Ryan_HubSpot’s avatar
    Ryan_HubSpot Customer published the disclosure report

    ()

  2. Ryan_HubSpot’s avatar
    Ryan_HubSpot Customer sent a message

    ()

  3. mega7’s avatar
    mega7 requested disclosure

    ()

  4. HubSpot Jira Application OAuth’s avatar
    HubSpot Jira Application OAuth changed the state to Resolved

    ()

  5. mega7’s avatar
    mega7 sent a message

    ()

  6. Abdul_hubspot’s avatar
    Abdul_hubspot Customer rewarded mega7 $50

    ()

    • Thanks for your submission! We'll get this over to the appropriate team for further review and remediation. Additionally, we're planning to take a closer look at the HTML injection vulnerabilities that are being triggered via email notifications to portal users so this may affect subsequent HTML injection vulnerabilities you submit that follow this same pattern.
  7. Abdul_hubspot’s avatar
    Abdul_hubspot Customer changed the state to Unresolved

    ()

  8. Abdul_hubspot’s avatar
    Abdul_hubspot Customer rewarded mega7 5 points

    ()

  9. mega7’s avatar
    mega7 sent a message

    ()

  10. mehmet_bugcrowd’s avatarbugcrowd logo
    mehmet_bugcrowd changed the state to Triaged

    ()

  11. mehmet_bugcrowd’s avatarbugcrowd logo
    mehmet_bugcrowd sent a message

    ()

  12. mega7’s avatar
    mega7 resolved a blocker for HubSpot by providing information on impact

    ()

  13. mega7’s avatar
    mega7 sent a message

    ()

  14. mrhacker_bugcrowd’s avatarbugcrowd logo
    mrhacker_bugcrowd created a blocker on the researcher to provide information on impact

    ()

  15. mrhacker_bugcrowd’s avatarbugcrowd logo
    mrhacker_bugcrowd sent a message

    ()

  16. mega7’s avatar
    mega7 created the submission

    ()