•  
      request #7840 XSS when importing artifacts in tracker
    Infos
    #7840
    Thomas Gerbet (tgerbet)
    2015-03-04 16:22
    2015-02-04 15:57
    7847
    Details
    XSS when importing artifacts in tracker

    XSS could be injected when artifacts are imported into a tracker v5.

    Impact

    An attacker could use this vulnerability to force a victim to execute uncontrolled code.
    CVSS2 score: 4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N)

    Exploitation

    An example is provided as attachment.

    References

    https://cwe.mitre.org/data/definitions/79.html
    https://www.owasp.org/index.php/Cross-site_Scripting_%28XSS%29

    Trackers
    All
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Empty
    Closed
    2015-02-05
    Attachments
    Trigger the vuln
    Tracker structure
    References

    Follow-ups