activemq-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Dejan Bosanac (JIRA)" <>
Subject [jira] [Created] (AMQ-4397) XSS vulnerability in scheduled.jsp
Date Thu, 21 Mar 2013 10:15:15 GMT
Dejan Bosanac created AMQ-4397:

             Summary: XSS vulnerability in scheduled.jsp
                 Key: AMQ-4397
             Project: ActiveMQ
          Issue Type: Bug
    Affects Versions: 5.8.0
            Reporter: Dejan Bosanac
            Assignee: Dejan Bosanac
             Fix For: 5.9.0

If string like {{* * * * *<script>alert(1)</script>}} is entered into cron of
a message, JS code will be executed on the scheduled.jsp page.

This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators
For more information on JIRA, see:

View raw message