Visiting a link such as the below will result in me reaching the correct ticket (IC-6948) - which suggests the input is being sanitised, however the window title (javascript document.title) is set to the full unsanitised input from the URL window:
This has been tested with version below:
Atlassian JIRA Project Management Software (v7.6.4#76006-sha1:ca83f0e)
I've attempted to do a XSS (Cross Site Scripting) attack with this, but I wasn't successful in closing the <head><title> tag, which I need to do before I can open a script tag in order to inject further input into the html page
Screenshot attached
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.