Comment by mmsc
4 months ago
>HackerOne declared the issue out of scope so I don't see why disclosure would make a difference here.
Indeed, but just you wait for Zendesk to say "well, _we_ didn't mark it out of scope!" as if delegating it to h1 renegades all responsibility.
They did, though. The post also quotes a response from Zendesk declaring it out of scope.