Stored XSS via cloud attachment
ZOHO Mail is a business mail that includes integrated calendar, contacts, notes, and tasks apps. Initially I was looking for a stored XSS in the webmail, but I did not find it so I started checking the other services. I wondered if it was possible to inject malicious code via attachments in ZOHO Notes. By attaching a local file it wasn’t, but in ZOHO Notes you can attach files from some cloud services: Google Drive, Dropbox, Box and Evernote. The XSS filters and protections worked well for the first three services, but not for Evernote. To my surprise it was possible to run javascript code in gadgets.zoho.eu via Evernote attachments. ...