Uploaded image for project: 'New Features 2017'
  1. New Features 2017
  2. NF-768

TSR Integration -> Security -> Cross Site Scripting(XSS)

    XMLWordPrintable

    Details

    • Type: Bug
    • Status: Closed
    • Priority: High
    • Resolution: Won't Do
    • Affects Version/s: None
    • Fix Version/s: None
    • Component/s: Integrations
    • Labels:
      None
    • Bug Type:
      Functional
    • Module:
      Platform - Security
    • Reported by:
      Harbinger
    • Item State:
      Stage QA - Production Deployment on Hold
    • Issue Importance:
      Q2
    • Dev Estimates:
      5
    • Code Reviewed By:
      Vijayendra Shinde

      Description

      Cross Site Scripting
      A Cross-Site Scripting (XSS) Scan attacks clients of the system under test by inserting dynamic code like JavaScript into the input, hoping that the same code is echoed in the response. However, this is only a problem if the response is consumed directly by a browser or if HTML is built in a naive way from the response. In other words, Cross-Site Scripting Scans may sometimes give you false positives.

      APIs :
      • Show Tours in Company
      GET https://stage.workterra.net/api/tours/getTours
      • Add Employee and Assign Tour
      POST https://stage.workterra.net/api/employee/addEmployeeTour

      • Alerts reported :
      • Sensitive Information Exposure: null/empty response body
      • Cross Site Scripting Detection: null/empty response body
      • Cross Site Scripting Detection: Content that is sent in request '<PLAINTEXT>' is exposed in response. Possibility for XSS script attack in: REST Request_GetTourList

      Please refer attached report for more details

        Attachments

          Activity

            People

            Assignee:
            kunal.kedari Kunal Kedari (Inactive)
            Reporter:
            prasadp Prasad Pise (Inactive)
            Developer:
            Saurabh Sablaka (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Dates

              Created:
              Updated:
              Resolved:
              Dev Due Date:
              Pre-Prod Due Date:
              Production Due Date:
              Code Review Date:

                Time Tracking

                Estimated:
                Original Estimate - 5h
                5h
                Remaining:
                Remaining Estimate - 0h
                0h
                Logged:
                Time Spent - 5h
                5h