Uploaded image for project: 'Crucible'
  1. Crucible
  2. CRUC-8638

Self-Cross-Site Scripting (XSS) on two administration pages

XMLWordPrintable

    • Icon: Public Security Vulnerability Public Security Vulnerability
    • Resolution: Fixed
    • Icon: Low Low
    • 4.8.14
    • 4.8.0, 4.8.13
    • None
    • None
    • 3.5

      The "Send test email" and "Universal Plugin Manager" pages, available for Crucible administrators only, were vulnerable to Self-XSS.

      Cross-Site Scripting (XSS) vulnerabilities are when user-controlled data in interpreted as code within the application. This can allow an attacker to inject JavaScript code that runs within the context of another user. Self-XSS is when the XSS vulnerability cannot be used to target other application users. This poses minimal risk but could be used in combination with an CSRF to cause the victim to trigger the XSS vulnerability.

              mparfianowicz Marek Parfianowicz
              mparfianowicz Marek Parfianowicz
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: