Mailbox Import errors not escaped

XMLWordPrintable

      • Go to "SpaceAdmin"
      • Select "Mailbox Import"
      • Specify location of mbox file on server with the XSS code, e.g. <script>alert('XSS')</script>
      • Submit the form
      • The embedded JavaScript is executed

              Assignee:
              Chris Broadfoot [Atlassian]
              Reporter:
              Anonymous
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

                Created:
                Updated:
                Resolved: