Uploaded image for project: 'Xray for Jira'
  1. Xray for Jira
  2. XRAY-6961

Stored XSS in "Requirements List" Gadget By "Fix Version" column

    XporterXMLWordPrintable

Details

    Description

      1. Create a fixversion for a project with the payload
        "><img src=x onerror=alert('Attacker')>
        
      1. Create a Requirement and add the fixversion to it
      2. Create a Dashboard and add the "Requirement List" gadget
      3. Choose the requirement project to be displayed in the gadget
      4. the payload will be reflect

      Attachments

        Activity

          People

            xcfe Xavier Fernandes [X] (Inactive)
            dpca Diamantino Campos
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Time Tracking

                Estimated:
                Original Estimate - 0 minutes
                0m
                Remaining:
                Remaining Estimate - 0 minutes
                0m
                Logged:
                Time Spent - 4 hours
                4h