Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-21023

screenshot-redirecter.jsp XSS attach via the afterURL parameter

    XMLWordPrintable

Details

    Description

      The screenshot-redirector.jsp does note escape the 'afterURL' URL parameter correctly, leading to an XSS attack vector.

      Attachments

        Activity

          People

            Unassigned Unassigned
            andreask@atlassian.com Andreas Knecht (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: