Uploaded image for project: 'WORKTERRA'
  1. WORKTERRA
  2. WT-10522

[Security] [ZAP-Active Scan Alert] Cross Site Scripting attack reflected on Forgot Password Page.

    Details

    • Type: Bug
    • Status: Open
    • Priority: High
    • Resolution: Unresolved
    • Affects Version/s: None
    • Fix Version/s: None
    • Component/s: None
    • Labels:
      None
    • Environment:
      Stage
    • Bug Type:
      Functional
    • Bug Severity:
      Medium
    • Level:
      Admin, Candidate, Employee, Partner
    • Module:
      Platform - Security
    • Reported by:
      Harbinger
    • Item State:
      Development - On Hold
    • Issue Importance:
      Must Have

      Description

      [Security] [ZAP-Active Scan Alert] Cross Site Scripting attack reflected on Forgot Password Page.

      This alert is reflected for following URL and
      URL : https://stage.workterra.net/Platform/Login/ForgotPassword
      Method: POST
      Parameter : SecretQuestionSecond
      Attack : " onMouseOver="alert(1);
      Evidence : " onMouseOver="alert(1);

      URL : https://stage.workterra.net/Platform/Login/ForgotPassword
      Method : POST
      Parameter : SecretQuestion
      Attack : " onMouseOver="alert(1);
      Evidence : " onMouseOver="alert(1);

      Testing is done on stage however issue might be present on production too.
      Please refer attached HTML report - point no 1 for more details.

      CC : Rakesh RoyHrishikesh DeshpandeSachin HingoleSamirVijayendra ShindeVijay SiddhaBharti SatputeGaurav SodaniNidhi Kaul

        Attachments

          Issue Links

            Activity

            prasadp Prasad Pise (Inactive) created issue -
            prasadp Prasad Pise (Inactive) made changes -
            Field Original Value New Value
            Link This issue relates to NF-2714 [ NF-2714 ]
            satyap Satya made changes -
            Assignee Satya [ ID10004 ] Jaideep Vinchurkar [ jaideep.vinchurkar ]
            jaideep.vinchurkar Jaideep Vinchurkar (Inactive) made changes -
            Assignee Jaideep Vinchurkar [ jaideep.vinchurkar ] Aditya Vishwakarma [ aditya.vishwakarma ]
            gaurav.sodani Gaurav Sodani (Inactive) made changes -
            Sprint WT Sprint 37 - Bugs [ 87 ]
            jaideep.vinchurkar Jaideep Vinchurkar (Inactive) made changes -
            Dev Due Date 20/Sep/2017
            jaideep.vinchurkar Jaideep Vinchurkar (Inactive) made changes -
            Item State Parent values: Development(10200)Level 1 values: On Hold(10207)
            jaideep.vinchurkar Jaideep Vinchurkar (Inactive) made changes -
            Dev Due Date 20/Sep/2017
            gaurav.sodani Gaurav Sodani (Inactive) made changes -
            Sprint WT Sprint 37 - Bugs [ 87 ]
            satyap Satya made changes -
            Environment_New Stage [ 18443 ]
            aditya.vishwakarma Aditya Vishwakarma (Inactive) made changes -
            Assignee Aditya Vishwakarma [ aditya.vishwakarma ] Santosh Balid [ santosh.balid ]
            Hide
            santosh.balid Santosh Balid (Inactive) added a comment -

            Please plan it in future sprints.

            Cc : Satya, Jaideep Vinchurkar, Bharti Satpute

            Show
            santosh.balid Santosh Balid (Inactive) added a comment - Please plan it in future sprints. Cc : Satya , Jaideep Vinchurkar , Bharti Satpute
            santosh.balid Santosh Balid (Inactive) made changes -
            Assignee Santosh Balid [ santosh.balid ] Gaurav Sodani [ gaurav.sodani ]
            vijayendra Vijayendra Shinde (Inactive) made changes -
            Assignee Gaurav Sodani [ gaurav.sodani ] Vijayendra Shinde [ ID10506 ]
            vijayendra Vijayendra Shinde (Inactive) made changes -
            Link This issue relates to DEV-13718 [ DEV-13718 ]

              People

              Assignee:
              vijayendra Vijayendra Shinde (Inactive)
              Reporter:
              prasadp Prasad Pise (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Dates

                Created:
                Updated:

                  Time Tracking

                  Estimated:
                  Original Estimate - 2h
                  2h
                  Remaining:
                  Remaining Estimate - 2h
                  2h
                  Logged:
                  Time Spent - Not Specified
                  Not Specified