-
Bug
-
Resolution: Fixed
-
Medium
-
2.0.3, 2.1.5, 2.2.10, 2.3.3, 2.4.5, 2.5.8, 2.6.2, 2.7.2
-
None
Vulnerable URL's:
- signup.action
- dosignup.action
on username, email, password, confirm, fullname
- is blocked by
-
CONFSERVER-9627 Velocity does not automatically escape HTML entities when substituting variables
-
- Closed
-
[CONFSERVER-11005] XSS vulnerability in signup actions
Workflow | Original: JAC Bug Workflow v3 [ 2876805 ] | New: CONFSERVER Bug Workflow v4 [ 3005390 ] |
Workflow | Original: JAC Bug Workflow v2 [ 2776851 ] | New: JAC Bug Workflow v3 [ 2876805 ] |
Status | Original: Resolved [ 5 ] | New: Closed [ 6 ] |
Workflow | Original: JAC Bug Workflow [ 2713662 ] | New: JAC Bug Workflow v2 [ 2776851 ] |
Workflow | Original: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2379323 ] | New: JAC Bug Workflow [ 2713662 ] |
Workflow | Original: Confluence Workflow - Public Facing - Restricted v5 [ 2269808 ] | New: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2379323 ] |
Workflow | Original: Confluence Workflow - Public Facing - Restricted v5.1 - TEMP [ 2215485 ] | New: Confluence Workflow - Public Facing - Restricted v5 [ 2269808 ] |
Workflow | Original: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2166587 ] | New: Confluence Workflow - Public Facing - Restricted v5.1 - TEMP [ 2215485 ] |
Workflow | Original: Confluence Workflow - Public Facing - Restricted v5 [ 1924099 ] | New: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2166587 ] |
Workflow | Original: Confluence Workflow - Public Facing - Restricted v3 [ 1726542 ] | New: Confluence Workflow - Public Facing - Restricted v5 [ 1924099 ] |
Workflow | Original: CONF Bug Subtask WF (TEMP) [ 1682374 ] | New: Confluence Workflow - Public Facing - Restricted v3 [ 1726542 ] |