Injection
- Blind XSS/HTML Injection
- HTML injection in email rendering
- XSS HTML Injection in email section
- Inject in message body
- Inject in subject/title
- Inject in reply field
- Email header injection (
\n,%0a)
tester'\"/><<h1>h1>ester0x88<</h1>/h1>
0x88"><<img/src=https://tinyurl.com/ynaeed3d>img/src=https://tinyurl.com/ynaeed3d>
Your Account has been suspended you should change your password From Here <a/href=https://evil.com>change password</a- Check execution in:
- Web UI
- Email notifications
Markup Injection
{% embed url="https://medium.com/@iframe_h1/a-picture-that-steals-data-ff604ba1012" %}
- Go to https://iplogger.org/
- Choose invisible
- Image send the message
IDOR
- Change message ID in request → access other users’ messages
- Change conversation/thread ID → view other conversations
- Modify user/client ID in requests
- Send message as another user
- Modify recipient ID
Improper Session Validation After Logout
- Access messages after logout
- Reuse old session token after logout
Privilege Escalation
- Reply to a thread you shouldn’t have access to
- Access deleted/archived messages via direct endpoint
- Client accessing firm staff messages
- Staff accessing unauthorized threads
Data Leakage in API Responses
- Inspect API responses for hidden fields
- Leak email addresses or internal IDs
- Check for data leakage across accounts
- Trigger errors → check for stack traces
- Message metadata leakage
Unauthenticated Access to APIs
- Access APIs without authentication
File Upload Issues
- Upload
.htmlfiles - Upload
.svgfiles - Upload
.jsfiles - Upload
PDFwith embeddedJS - Double extensions (
file.jpg.html) - Bypass
Content-Typevalidation - Inject payload in filename
- Access uploaded files via direct URL
- Modify sender ID
- Access other users’ attachments (IDOR)
Leaked Sensitive Information in Email Notifications
- Email contains full message content
- Email leaks sensitive data like emails
- Email exposes internal IDs or hidden fields
- Secure messaging leaks via email
Rate Limit Issues
- Check rate limiting
- Trigger multiple notifications (spam)
- Race Condition
- Send high volume of messages quickly
- Email bombing via notifications
- Very long messages (10k+ chars) ->
DoS Potential
BAC
- Replay request (duplicate messages)
- Modify message content after sending
- Send message when messaging is disabled
- Send message when user is blocked
- Bypass client/staff messaging restrictions
CSRF
- Build CSRF PoC (auto-send message)
Improper Input Validation
- Unicode / RTL text
- Emojis
- Null byte injection (
%00) - Broken JSON / missing parameters