Uploaded image for project: 'Xray for Jira'
  1. Xray for Jira
  2. XRAY-6395

Stored XSS in "Test Run Assignee & Executed by" in "Test Execution Page"

    XporterXMLWordPrintable

Details

    • XRAY 2020 Sprint 4
    • OK

    Description

      Steps:

      1. Go to profile > Edit fullname or username to <script>alert("XSS")</script>
      2. Create a test case > Execute this test case > Go to Execution detailhttp://192.168.10.100:8080/secure/XrayExecuteTest!default.jspa?testExecIssueKey=<testExecIssueKey>&testIssueKey=<testIssueKey>
      3. Click to Assignee > XSS will be trigged.

      Attachments

        Activity

          People

            dpca Diamantino Campos
            dpca Diamantino Campos
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Time Tracking

                Estimated:
                Original Estimate - Not Specified
                Not Specified
                Remaining:
                Remaining Estimate - 0 minutes
                0m
                Logged:
                Time Spent - 3 hours
                3h