•  
      request #40459 XSS in Gantt chart
    Infos
    #40459
    Nicolas Terray (nterray)
    2024-12-09 14:53
    2024-11-18 13:50
    42112
    Details
    XSS in Gantt chart

    XSS could be injected in Gantt (graphs on tracker plugin) using title of an artefact.

    Impact

    An attacker could use this vulnerability to force a victim to execute uncontrolled code.
    CVSSv3.1 score: 5.4 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)

    Exploitation

    In a sprint tracker, have a Gantt chart with Start date = start date, Due date = end date, Finish date = end date, summary = Sprint name. Create a sprint named Sprint "'<script>alert(1)</script> A with an end date but no start date. Create another sprint named Sprint "'<script>alert(1)</script> B with a start date and an end date.

    Go to gantt chart, there should not be any alert displayed.

    References

    CWE 79
    OWASP Cross-site Scripting
    CVE-2024-52599

    Trackers
    All
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Nicolas Terray (nterray)
    Closed
    2024-11-18
    Attachments
    Empty
    References

    Follow-ups

    User avatar
    Thomas Gerbet (tgerbet)2024-11-25 09:36

    CVE-2024-52599 has been assigned to this issue.


    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes
    User avatar
    Thomas Gerbet (tgerbet)2024-11-18 15:04
    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes