Stored XSS via link with Word file leads to leaks JWT token

Description

From Bugcrowd:

I found an stored XSS vulnerability via Word file when embed the link. As an attacker, I can enter a phishing/malware website or take JWT auth. If successful, a XSS attack can severely impact websites and web applications, damage reputation and relationships with customers. XSS can deface websites, can result in compromised user accounts, and can run malicious code on web pages, which can lead to a compromise of the user’s device.

Steps to reproduce:

  1. Create a Macro with Word as Input and Attachment as Source

  2. Select the .docx file containing XSS injection as attachment:

  3. Save the macro and publish the page

  4. Click on the link in the macro

Activity

Andrzej Kaliciecki 16 June 2026, 14:29

Confirmed fixed in QA env.