Details
-
Bug
-
Status: Closed
-
Major
-
Resolution: Done
-
None
-
XRAY 2020 Sprint 7
-
Description
Steps:
- Create Two Test Issue (A) and (B).
- Go to Test Issue A and from Test Details section click in Add step button Fill out the fields and click Add.
Exploit:
- Malicious user Go to Test Step Custom Fields
- Click in Create button to Custom fields.|
- In name filed inject XSS Payload. and Make this field required
- Now if any other user/Admin go to Test issue B and try import step issue. the XSS payload reflected on target browser.
- Just change the data to "Don't map this field" to have the validate button enabled