Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-36083

XSS when attaching a file to an issue

    XMLWordPrintable

Details

    Description

      Hi,

      I found a persistent XSS vulnerability when attaching a file to an issue.
      The steps to reproduce are the following :

      • Attach a file to an issue. Its name must contain "<script>alert('XSS')</script>". I used a python script to do that.
      • Browse to the issue and open the ALL tab under activity. A popup should appear.

      See the attachment for the result.

      Attachments

        Issue Links

          Activity

            People

              rtekhov Roman Tekhov (Inactive)
              6feda85e9c6f Yohan Joubert
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: