Please log in to bookmark issues
#2890 – 
Confirmed
Bug report
0
Click to toggle a vote for this issue
0
0 + 0
Time tracking started at Paused
Description

Attackers can execute malicious scripts on other users' computers. They can do this by entering JavaScript code in different URL parameters such as “fs[project_id][o]”, “fs[project_id][v]”, “fs[issuetype][o]”,etc. on the “search” functionality, which belongs to the “Issues” page. The malicious user would have to lure the victim to follow a link in order to have the attack executed on the victim's computer.

Attachments0
 zegenie
Jun 27, 2020 (10:57)
Cancel

 @thnguyen is this a duplicate or variant of issue #2887 ?

Important details
User pain
  • Type of bug
    Not triaged
  • Likelihood
    Not triaged
  • Effect
    Not triaged
Times and dates
  • Estimated time No time estimated
People involved
Other details
  • Not determined