XSS in FilterSubscription

XMLWordPrintable

    • 6.02
    • 5.8

      To reproduce:

      1. Visit:
        /secure/FilterSubscription!default.jspa?returnUrl=javascript:alert(1)
        
      2. Click "Cancel"
      3. An alert should appear

      This URL should be restricted to the current domain, and to http/https protocols.

              Assignee:
              Oswaldo Hernandez (Inactive)
              Reporter:
              Tony Boyle
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

                Created:
                Updated:
                Resolved: