-
Bug
-
Resolution: Fixed
-
Low
-
4.8
-
NOTE: This bug report is for JIRA Cloud. Using JIRA Server? See the corresponding bug report.
A JIRA administrator(a user who is a member of the jira-administrators group) can create a persistent XSS that affects the /project/ViewDefaultProjectRoleActors.jspa resource through a role name.
- is related to
-
JRASERVER-61861 CVE-2016-4318: XSS vulnerability in role name on /project/ViewDefaultProjectRoleActors.jspa
- Closed