Uploaded image for project: 'Jira Cloud (including JIRA Core)'
  1. Jira Cloud (including JIRA Core)
  2. JRACLOUD-61861

CVE-2016-4318: XSS vulnerability in role name on /project/ViewDefaultProjectRoleActors.jspa

    XMLWordPrintable

    Description

    NOTE: This bug report is for JIRA Cloud. Using JIRA Server? See the corresponding bug report.

    A JIRA administrator(a user who is a member of the jira-administrators group) can create a persistent XSS that affects the /project/ViewDefaultProjectRoleActors.jspa resource through a role name.

      Attachments

        Issue Links

          Activity

            People

            Assignee:
            Unassigned
            Reporter:
            lukasz.plonka324392336 lukasz.plonka324392336
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Dates

              Created:
              Updated:
              Resolved: