•  
      request #7828 XSS in graphs on tracker plugin
    Infos
    #7828
    Thomas Gerbet (tgerbet)
    2015-03-04 16:22
    2015-02-02 16:52
    7835
    Details
    XSS in graphs on tracker plugin

    XSS could be injected in graphs on tracker plugin using URL parameters or an artefact.

    Impact

    An attacker could use this vulnerability to force a victim to execute uncontrolled code.
    CVSS2 score : 4 (AV:N/AC:L/Au:S/C:N/I:P/A:N)

    Exploitation

    Create a report on a artifact with name containing something like <script>alert(1)</script>.

    Edit a report with a name containing something like <script>alert(2)</script>.

    References

    https://cwe.mitre.org/data/definitions/79.html
    https://www.owasp.org/index.php/Cross-site_Scripting_%28XSS%29

    Trackers
    All
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Empty
    Closed
    2015-02-05
    Attachments
    Empty
    References

    Follow-ups

    User avatar
    Thomas Gerbet (tgerbet)2015-02-03 14:00
    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes
    User avatar
    Thomas Gerbet (tgerbet)2015-02-02 17:12

    • Summary
      -Reflected XSS in graphs on tracker plugin 
      +XSS in graphs on tracker plugin 
    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes
    • Status changed from Under implementation to Under review