Uploaded image for project: 'FishEye'
  1. FishEye
  2. FE-5017

XSS in the view parameter of several actions

    XMLWordPrintable

Details

    Description

      The following XSS issues were detected by a customer.

      • /changelog?max=30&view=cru%22;alert(4015891);//%22&@asv=cru
      • /project/CR?max=30&projectKey=CR&view=all";alert(3166631);//"&@asv=all
      • /user/c30626?max=30&name=c30626&view=all";alert(1287220);//"&@asv=all

      Attachments

        Activity

          People

            Unassigned Unassigned
            dblack David Black
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: