Details
-
Bug
-
Status: Closed
-
Major
-
Resolution: Done
-
R3.5.3
Description
Site-wide CSRF on admin settings page:
Â
Endpoints confirmed too be vulnerable:
POST /secure/admin/views/XrayIssueTypeMappingConfiguration!save.jspa
POST /secure/admin/views/XrayRequirementCoverageConfiguration!save.jspa
POST /secure/admin/views/XrayTestStatusConfiguration!save.jspa
POST /secure/admin/views/XrayTestStatusConfiguration!delete.jspa
POST /secure/admin/views/XrayTestStatusConfiguration!savePrefs.jspa
POST /secure/admin/views/XrayColumnLayoutConfiguration!save.jspa
POST /secure/admin/views/XrayCustomFieldConfiguration!save.jspa