Contact Administrators Form is enabled by default

XMLWordPrintable

    • 4
    • Severity 3 - Minor

      On OnDemand instances, the feature is enabled by default at
      <instanceURL>/secure/admin/ViewApplicationProperties.jspa when the documentation Configuring JIRA Options specifies that it should be Default: OFF

      This causes that on every OnDemand instance, the URL <instanceURL>/secure/ContactAdministrators!default.jspa provides a form that anyone can send messages with to administrators.

      It could be security problem as it doesn't contain a captcha.

            Assignee:
            Shubham Raj
            Reporter:
            Mauro Badii (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

              Created:
              Updated:
              Resolved: