[1] https://gist.github.com/hackermondev/68ec8ed145fcee49d2f5e2b...
[1] https://gist.github.com/hackermondev/68ec8ed145fcee49d2f5e2b...
Yes, the researcher could have tee'd himself up better, but this says way more about zendesk than it does about the 15-year-old researcher.
It's possible that some chains could have credentials or other sensitive information in ticket chains.
Clearly Zendesk needs to change things so that the email address that is created for a ticket isn’t guessable.
Of course, this is only a good strategy if you're just wanting to do a good deed and not counting on getting more than a thank you note, but Zendesk or Hackerone (whoever you want to blame here) didn't even accept the bug in the first place. That's the problem here, not the omission of an exploit chain
We add impact demonstrations to a few findings per pentest report because our audience is broader: the nontechnical people who decide to allocate the money need to understand why this is useful and that the devs/sysadmins need to get enough time to do things right (developers and sysadmins are often sufficiently skilled, but are under delivery pressure). A sufficiently technical team, when the bug is adequately explained, doesn't need a functional exploit to see it's real/impactful or not