If someone enters Javascript in a Defect description, for example one for cross site scripting, it will be executed when loading the task board.
So entering in a description will cause a pop up to appear anytime you load the task board.
Help get this topic noticed by sharing it on
Twitter,
Facebook, or email.
Twitter,
Facebook, or email.
-
I can reproduce this issue by entering a script block in a non-html description field and then hovering over the work item on either board to trigger the detailed tooltip popup. The script will be executed in this context. However, it does not run automatically simply by reloading the task board. I may have missed something however. Do you have any further details you could provide us with?
-
-
-
-
-
This is pretty much the same as I have tested here and the alert only pops up when hovering over the work item title (which is still a bug). Just refreshing the board does not make it show up. Have you configured the description field to appear in one of the customizable sections? I am trying to understand why it appears all the time on your side.
-
-
-
Loading Profile...






