Uploaded image for project: 'Xporter for Jira'
  1. Xporter for Jira
  2. XPORTER-3518

Stored XSS on Process Manager by User Name field value (Data Center)

    XporterXMLWordPrintable

Details

    • JIRAXPORTER 2020 Sprint 3
    • OK

    Description

      After install Xporter for server. go to Process Manager Taps. The main objective of this page is to give the Admin the possibility to see export Process and mange this exported Process. So if attacker make a user privilege change account name to XSS Payload then go to issues, click in Xporter and click in export. Now any Admin's go to Process Manager_ the XSS Payload is reflected in the victim's browser

      Attachments

        Issue Links

          Activity

            People

              rmbr Rui Rodrigues
              rmbr Rui Rodrigues
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0 minutes
                  0m
                  Logged:
                  Time Spent - 1 day, 1 hour
                  1d 1h