Details
-
Bug
-
Status: Closed (View Workflow)
-
Critical
-
Resolution: Done
-
prod/bigpicture/jiracloud/2020/05/21/14_45, prod/biggantt/jiracloud/2020/05/21/14_45, prod/bigpicture/jiraserver/2020/06/23/7.11.15, prod/biggantt/jiraserver/2020/06/23/4.9.15
-
None
-
[Inactive] Just Gantt
-
BigPicture, BigGantt
-
JIRA server, JIRA cloud
-
5
-
1
-
No
-
-
Sprint 2020/14
-
6 days, 19 hours, 10 minutes, 47 seconds -
2 hours, 13 minutes, 58 seconds -
40 minutes, 47 seconds -
34 minutes -
3 minutes, 2 seconds -
1 minute, 48 seconds -
2 days, 2 hours, 48 minutes, 40 seconds -
Description
https://tracker.bugcrowd.com/softwareplant-blitz/submissions/c47850fe-8662-4102-bf68-ba5e899ed80f
CVSS v3 >= 4.0 Medium
Accepted on 17.06.2020
Due date: 12.08.2020
Steps to reproduce:
- Create a Gantt marker with stored XSS script as the name (example: <img src=x onerror=alert(/marker/)>
- Refresh the page
Result:
The script is executed automatically.
Expected result:
The script should not be executable