Stored XSS in Team Links

Disclosed by
Vj1naruto
  • Engagement Atlassian
  • Disclosed date 5 months ago
  • Reward $600
  • Priority P3 Bugcrowd's VRT priority rating
  • Status Resolved This vulnerability has been accepted and fixed
Summary by Atlassian

Stored XSS Vulnerability in Team Links

Summary by Vj1naruto

Off-domain XSS via Jira team's link using data URI in jira cloud.

Activity