-
Type:
Bug
-
Resolution: Fixed
-
Priority:
High
-
Affects Version/s: 5.0.3
-
Component/s: None
-
5
-
5
The administration screen which facilitates the addition of new custom field options is vulnerable to csrf, as it does not check that the atl_token submitted is in fact legitimate for the user submitting it (you can put in any value for the token field).
To access this screen you can go to a url similar to the following ( it is linked off the issue custom fields administration page (/secure/admin/ViewCustomFields.jspa) ):