Uploaded image for project: 'Xray for Jira'
  1. Xray for Jira
  2. XRAY-4471

XSS, In the Automated Steps Library page, in case of a syntax error, it is possible to execute JS text

    XporterXMLWordPrintable

Details

    • XRAY 2020 Sprint 10
    • OK

    Description

      In the Automated Steps Library page, in case of a syntax error, it is possible to execute JS text.

      Steps to Reproduce:
      1) Create a new Cucumber Test
      2) Add a new Step: When I do stuff
      3) Go to the Automated Steps Library
      4) Edit the step created in 2) and replace with the following text:

      When I do stuff
      <script>alert(1);</script>
      

      5) Click "Save"

      Result: a popup will be displayed will appear
      Expected: the HTML tags should not be processed


      Attachments

        1. Screenshot at Sep 18 17-49-24.png
          130 kB
          Hugo Braz [X]
        2. Screenshot at Sep 18 17-50-25.png
          149 kB
          Hugo Braz [X]

        Activity

          People

            prpa Paulo Alves
            hslb Hugo Braz [X] (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Time Tracking

                Estimated:
                Original Estimate - 0 minutes
                0m
                Remaining:
                Remaining Estimate - 0 minutes
                0m
                Logged:
                Time Spent - 25 minutes
                25m