Summary by Atlassian
Stored XSS on Portfolio in Jira Cloud
Stored XSS on Portfolio in Jira Cloud
3 years ago :v
Jira Work Management Cloud formerly Jira Core (bugbounty-test-<bugcrowd-name>.atlassian.net)
Web App
https://bugbounty.atlassian.net/secure/PortfolioPlanManage.jspa
Hello,
My self Abdulwahab,
I am Writing this to You because i Found Stored Xss in Your Website.
1.Login
2.Go to Portfolio> Create New Plan
3.in Name Section add the Malicious Javascript Code i.e,
"><script>alert(document.domain);</script>
4.Then Choose Filters any Filter
5.Then Next>Next>Next> Done
6.XSS BOOOOOM!
https://youtu.be/mBK5uniY-3g
Thanks,
Abdulwahab,
Independent Cyber Security Researcher,