XSS vulnerability in JIRA description field

XMLWordPrintable

    • 6
    • 6.5

      Using a link like:

      https://x.x.com/x=[# please click here onmousemove=alert(1) _] 
      

      shows a serious XSS vulnerability - using error correction in browsers (Firefox 24) - in the JIRA description field (and most likely every other wiki-style rendered field).

      Example:
      https://x.x.com/x=[# please click here onmousemove=alert(1) _]

      Please fix asap. For further information pls. contact me.

      Cheers
      Kai

            Assignee:
            Oswaldo Hernandez (Inactive)
            Reporter:
            Kai Gottschalk
            Votes:
            0 Vote for this issue
            Watchers:
            5 Start watching this issue

              Created:
              Updated:
              Resolved: