Please log in to bookmark issues
#2888 – 
Confirmed
Bug report
0
Click to toggle a vote for this issue
0
0 + 0
Time tracking started at Paused
Description

The HTML parameters associated with the create, modify, and delete items functionalities are not properly validated for the user input and can be exploited for carrying out a cross-site request forgery (XSRF) attack. As a result, an attacker can send a request to report a “Bug”, “Improvement Request”, “Task” or “Feature Request”, embedding malicious code which will be stored in the database, and attaching executable files or XSS via files.

How to reproduce
Attachments0
/unthemed/mono/no-comments.png
Expand, collaborate and share
Post a comment and get things done
Important details
User pain
  • Type of bug
    Not triaged
  • Likelihood
    Not triaged
  • Effect
    Not triaged
Times and dates
  • Estimated time No time estimated
People involved
Other details
  • Not determined