Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-21019

runportleterror.jsp contains XSS hole

    XMLWordPrintable

Details

    Description

      The runportleterror.jsp contains an XSS attach vector via the unescaped 'portletKey' URL parameter. The parameter should be escaped properly.

      Attachments

        Activity

          People

            Unassigned Unassigned
            andreask@atlassian.com Andreas Knecht (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: