Details
-
Bug
-
Resolution: Fixed
-
Blocker
-
0.11
-
None
-
None
Description
It's possible to exploit the title of CR to perform injection.
Reproduction step:
- Create a new CR with a title {{/html asyncgroovy}}println("Hello from groovy!"){{/groovy/async}}
- With admin user go to see that CR
Expected result:
- the title should not be executed
Obtained result:
- the title is executed in the sheet of the CR
Attachments
Issue Links
- is caused by
-
CRAPP-64 Authors without edit rights should be able to edit title of CR
- Closed