-
Bug
-
Resolution: Fixed
-
High
-
3.12, 3.12.1, 3.12.2, 3.12.3, 3.13, 3.13.1, 3.13.2, 3.13.3, 3.13.4, 3.13.5, 4.0, 4.0.1, 4.0.2, 4.1
-
3.12
-
The issuelinkssmall.jsp has an XSS hole, where if the URL contains an XSS string, the ww:url tag will include that tag in the page because the value attribute was left empty.
- is duplicated by
-
JRASERVER-20665 xss vulnerability in issuelinksmall.jsp
-
- Closed
-