•  
      request #7847 Persistent XSS in project sidebar
    Infos
    #7847
    Thomas Gerbet (tgerbet)
    2015-03-04 16:22
    2015-02-05 15:19
    7853
    Details
    Persistent XSS in project sidebar

    A persistent XSS could be injected into the sidebar of a project.

    Impact

    An attacker could use this vulnerability to force a victim to execute uncontrolled code.
    CVSS2 score: 3.5 (AV:N/AC:M/Au:S/C:N/I:P/A:N)

    Exploitation

    As a project admin create or edit a service and put "><script>alert(1)</script><" in the service link.

    References

    https://cwe.mitre.org/data/definitions/79.html
    https://www.owasp.org/index.php/Cross-site_Scripting_%28XSS%29

    Project admin
    All
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Empty
    Closed
    2015-03-02
    Attachments
    Empty
    References

    Follow-ups

    User avatar
    Merged in 7.10.99.59

    • Status changed from Under review to Closed
    • Close date set to 2015-03-02