Uploaded image for project: 'Xray for Jira'
  1. Xray for Jira
  2. XRAY-6615

Stored XSS at Xray in Test issue by Import Steps issue

    XporterXMLWordPrintable

Details

    • XRAY 2020 Sprint 7
    • OK

    Description

      Steps:

      1. Create Test Issue (A).
      2. Go to Test Issue A and from Test Details section click in Add step button Fill out the fields and click Add.

      Exploit:

      1. Malicious user Go to Test Step Custom Fields
      2. Click in Create button to Custom fields.|
      3. In name filed inject XSS Payload. and Make this field required
      4. Add Steps to Test A
      5. Go to Issue search view and make sure the column "Manual Test Step" is added => The exploit will be reflected
      6. Go to a Test Execution and click on "Add Tests" and then go to search tab and search for tests making sure the Test A is displayed and the column "Manual Test Step" is displayed as well =>The exploit will be reflected

       

       

      Attachments

        Issue Links

          Activity

            People

              masg Marco Guedes
              dpca Diamantino Campos
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - 0 minutes
                  0m
                  Remaining:
                  Remaining Estimate - 0 minutes
                  0m
                  Logged:
                  Time Spent - 5 hours
                  5h