Uploaded image for project: 'Xray for Jira'
  1. Xray for Jira
  2. XRAY-4743

Reflected XSS in secure/TestStepExportAction!default.jspa

    XporterXMLWordPrintable

Details

    • OK

    Description

      Reflected XSS in secure/TestStepExportAction!default.jspa. A reflected XSS was found in /secure/TestStepExportAction!default.jspa via the key parameter. Some encoding is done on the payload since it gets converted to uppercase.
      To verify, browse the following link in Firefox:
      [Server]/secure/TestStepExportAction!default.jspa?key=[TEST KEY]><svg/onload="%26%23x61%3b%26%23x6 C%3b%26%23x65%3b%26%23x72%3b%26%23x74%3b%26%23x28%3b%26%23x31%3b%26%23x29%3b">&exportTyp e=CSV&decorator=dialog&inline=true&_=1574154808724

      Attachments

        Activity

          People

            prpa Paulo Alves
            hslb Hugo Braz [X] (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Time Tracking

                Estimated:
                Original Estimate - 0 minutes
                0m
                Remaining:
                Remaining Estimate - 0 minutes
                0m
                Logged:
                Time Spent - 1 day, 6 hours
                1d 6h