Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-35084

XSS in admin/ViewIssueFields.jspa

    XMLWordPrintable

Details

    Description

      Reproduction:
      1. Create custom fields with <script>alert(1)</script> in name and/or description.
      2. Go to 'Field Configurations'
      3. Click 'Add Field Configuration', enter any text in 'Name'
      4. Hit okay and wait for the page to refresh
      5. Choose the config you just made -> XSSed

      Attachments

        Issue Links

          Activity

            People

              izinoviev Ilya Zinoviev (Inactive)
              ablackmore Ashley Blackmore
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: