The Intercom plugin up to and including 1.2.1 for WordPress leaks a Slack Access Token in source code. An attacker can obtain a lot of information about the victim's Slack (channels, members, etc.).
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
intercom intercom |