-
Bug
-
Resolution: Fixed
-
Low
-
None
-
4.8
-
NOTE: This bug report is for JIRA Server. Using JIRA Cloud? See the corresponding bug report.
A JIRA administrator(a user who is a member of the jira-administrators group) can create a persistent XSS that affects the /project/ViewDefaultProjectRoleActors.jspa resource through a role name.
- relates to
-
JRACLOUD-61861 CVE-2016-4318: XSS vulnerability in role name on /project/ViewDefaultProjectRoleActors.jspa
- Closed