Uploaded image for project: 'Xray for Jira'
  1. Xray for Jira
  2. XRAY-7486

XSS on Document Generator template description

    XporterXMLWordPrintable

Details

    • XRAYSERVERDG 2021 SPRINT 6
    • OK

    Description

      Xray is vulnerable to XSS by injecting malicious javascript on the template description.

      Steps to reproduce:

      • Add malicious javascript to the template description
        "><img src=x onerror=javascript:alert(1)>
      • Go to an issue and click on Xray Document Generator dialog to export a single issue
      • Hover the question mark and the javascript will run

      Remediation steps: Sanitize template description

      Attachments

        Activity

          People

            afro Andre Fernandes Rodrigues
            prpa Paulo Alves
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Time Tracking

                Estimated:
                Original Estimate - Not Specified
                Not Specified
                Remaining:
                Remaining Estimate - 0 minutes
                0m
                Logged:
                Time Spent - 2 hours, 30 minutes
                2h 30m