-
Bug
-
Resolution: Fixed
-
Medium (View bug fix roadmap)
-
None
-
None
NOTE: This bug report is for JIRA Software Server. Using JIRA Software Cloud? See the corresponding bug report.
This is difficult to reproduce - needs tampering with the post data for the page.
On Classic Board, go to the search box. Tamper with the posted data and add the parameter redirectURL with something like:
redirectType=xxx"><img src=u onerror=alert(1)>
(Note: it doesn't work if you use <script></script> tags)
You need to have > 1 page of search results - more than 30 by default, or change the Issues Per Page in the Tools > User Preferences section.
The image is rendered within the page numbers.
- relates to
-
JSWSERVER-5562 XSS (reflected) in rankVMID parameter of GetRankPage.jspa
-
- Closed
-
-
JSWCLOUD-6705 XSS in redirectType parameter on SearchBoard.jspa
-
- Closed
-
[JSWSERVER-6705] XSS in redirectType parameter on SearchBoard.jspa
Workflow | Original: JAC Bug Workflow v2 [ 2850734 ] | New: JAC Bug Workflow v3 [ 2933951 ] |
Status | Original: Resolved [ 5 ] | New: Closed [ 6 ] |
Workflow | Original: JIRA Bug Workflow w Kanban v7 - Restricted [ 2545396 ] | New: JAC Bug Workflow v2 [ 2850734 ] |
Workflow | Original: JIRA Bug Workflow w Kanban v6 - Restricted [ 1551745 ] | New: JIRA Bug Workflow w Kanban v7 - Restricted [ 2545396 ] |
Description |
Original:
This is difficult to reproduce - needs tampering with the post data for the page.
On Classic Board, go to the search box. Tamper with the posted data and add the parameter redirectURL with something like: redirectType=xxx"><img src=u onerror=alert(1)> (Note: it doesn't work if you use <script></script> tags) You need to have > 1 page of search results - more than 30 by default, or change the Issues Per Page in the Tools > User Preferences section. The image is rendered within the page numbers. |
New:
{panel:bgColor=#e7f4fa} *NOTE:* This bug report is for *JIRA Software Server*. Using *JIRA Software Cloud*? [See the corresponding bug report|http://jira.atlassian.com/browse/JSWCLOUD-6705]. {panel} This is difficult to reproduce - needs tampering with the post data for the page. On Classic Board, go to the search box. Tamper with the posted data and add the parameter redirectURL with something like: redirectType=xxx"><img src=u onerror=alert(1)> (Note: it doesn't work if you use <script></script> tags) You need to have > 1 page of search results - more than 30 by default, or change the Issues Per Page in the Tools > User Preferences section. The image is rendered within the page numbers. |
Link |
New:
This issue relates to |
Workflow | Original: JIRA Bug Workflow w Kanban v6 [ 909301 ] | New: JIRA Bug Workflow w Kanban v6 - Restricted [ 1551745 ] |
Labels | Original: security | New: cvss-high security |
Workflow | Original: GreenHopper Kanban Workflow 20141014 [ 745843 ] | New: JIRA Bug Workflow w Kanban v6 [ 909301 ] |
Workflow | Original: GreenHopper Kanban Workflow v2 [ 449341 ] | New: GreenHopper Kanban Workflow 20141014 [ 745843 ] |
Labels | Original: advisory-pending security | New: security |
Security | Original: Reporters and Developers [ 10021 ] |