Uploaded image for project: 'Xray for Jira'
  1. Xray for Jira
  2. XRAY-4692

XSS vulnerabilities in Test Run page

    XporterXMLWordPrintable

Details

    • OK

    Description

      There are (at least) two XSS vulnerabilities (JS code injection) into the HTML code of the Test Run page.

      This was reproduced in Jira 7.13.1 (however, any version should do it) and Xray 3.5.3.

      Steps to reproduce (Generic field entry point):

      1. Create a new Generic Test issue
      2. In the Generic Test Definition field write: <script>alert("XSS")</script>
      3. Create a new Test Run: “Execute In” -> “New Test Execution”
      4. Open the Test Run page -> You will see the alert in the page

      Steps to reproduce (Pre-Condition Summary entry point):

      1. Create a new Test
      2. In the Test Issue click on "Create Pre-Condition"
      3. In the summary field write: <script>alert("XSS PreCond")</script>
      4. Create a new Test Run: “Execute In” -> “New Test Execution”
      5. Open the Test Run page -> You will see the alert in the page

      Attachments

        Issue Links

          Activity

            People

              prpa Paulo Alves
              hslb Hugo Braz [X] (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - 0 minutes
                  0m
                  Remaining:
                  Remaining Estimate - 0 minutes
                  0m
                  Logged:
                  Time Spent - 2 days, 6 hours, 30 minutes
                  2d 6h 30m