Project description is persistent XSS vector for project admins

XMLWordPrintable

    • 4.03
    • 7.1

      This issue is a clone of another one that was fixed in OD but left unfixed in BTF as "admin xss". It has been pointed out by several customers that this exploit requires only project admin level of privilege.

      The following project description:

      <script>alert(1)</script>
      

      Pops up in the view project page, the admin page for the project, etc.

            Assignee:
            Oswaldo Hernandez (Inactive)
            Reporter:
            Andre Lehmann
            Votes:
            0 Vote for this issue
            Watchers:
            9 Start watching this issue

              Created:
              Updated:
              Resolved: