Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-28153

The "user" Dark Features page is vulnerable to XSRF/csrf

    XMLWordPrintable

Details

    Description

      The "User Dark Features" page located at $host/secure/ViewProfile.jspa?selectedTab=jira.user.profile.panels:up-darkfeatures-panel allows users to add dark features which only affect themselves. However, it is not protected against XSRF attacks. Note: the 'value' of dark features is not properly encoded when output into a javascript context (if one is to enter ' + eval(alert(1) ) + ' as a dark feature then an alert dialogue with the number one in it will be shown on every page) so the impact of this vulnerability includes XSS

      Attachments

        Issue Links

          Activity

            People

              edalgliesh Eric Dalgliesh
              dblack David Black
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: