[emailext-template] Admin only XSS

This issue is archived. You can view it, but you can't modify it. Learn more

XMLWordPrintable

      Description

      Email Extension Template does not escape the name of the Email template Management in the onclick attribute.

      This results in a stored cross-site scripting (XSS) vulnerability exploitable only by attackers with Overall/Administer permission.

      We don't consider it a security vulnerability, because you need administer permission to exploit it and as an administer you can already do all the impact of a XSS.

      Recommendation

            Assignee:
            Unassigned
            Reporter:
            Kevin Guerroudj
            Archiver:
            Jenkins Service Account

              Created:
              Updated:
              Archived: