Uploaded image for project: 'Xporter for Jira'
  1. Xporter for Jira
  2. XPORTER-3494

Stored XSS in AuditLogs by User Name field value

    XporterXMLWordPrintable

Details

    • JIRAXPORTER-2020 Sprint 1
    • OK

    Description

      Steps:

      1. The attacker accesses his account and changes its name to an XSS payload
      2. The attacker go to any issue, and from the "Xporter" section he exports the issue.
      3. Now any Admin/Users go to AuditLogs_ the XSS Payload is reflected in the victim's browser

      Attachments

        Activity

          People

            jmlg Joao Goncalves [X] (Inactive)
            rmbr Rui Rodrigues
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Time Tracking

                Estimated:
                Original Estimate - 0 minutes
                0m
                Remaining:
                Remaining Estimate - 0 minutes
                0m
                Logged:
                Time Spent - 2 hours
                2h