[#10141] - JasperReports Server vulnerable to Stored Cross Site Scripting

Category:
Patch
Priority:
High
Status:
New
Project: Severity:
Major
Resolution:
Open
Component: Reproducibility:
Not Attempted
Assigned to:

When creating a new dashboard, it is possible to include an external webpage. If this source contains javascript then it is executed.
URL : jasperserver/dashboard/designer.html

With this kind of dashboard, if shared, hackers can, for example, create fake authentication forms to steal logins and passwords.

AttachmentSize
Image icon storedxss.png90.33 KB
v6.3.0
JasperReports Server
thomas.penne's picture
Joined: Nov 24 2017 - 5:38am
Last seen: 5 years 2 months ago
Feedback