Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-11027

XSS vulnerabilities in create/edit/copy page and blogpost actions

    • Icon: Bug Bug
    • Resolution: Fixed
    • Icon: Medium Medium
    • 2.7.3
    • 2.1.5, 2.2.10, 2.3.3, 2.4.5, 2.5.8, 2.6.2, 2.7.2
    • None

      The following create/edit page URL's are vulnerable:

      • /pages/createpage.action
      • /pages/docreatepage.action
      • /pages/editpage.action
      • /pages/doeditepage.action

      on parentPageString, mode, labelsString, captchaId

      The following create/edit blogpost URL's are vulnerable:

      • /pages/createblogpost.action
      • /pages/docreateblogpost.action
      • /pages/editblogpost.action
      • /pages/doeditblogpost.action

      on mode, labelsString, title, captchaId

      The following copy page URL's are vulnerable:

      • /pages/copypage.action
      • /pages/docopypage.action

      on parentPageString, mode, labelsString, captchaId

      The following comment action URL's are vulnerable:

      • pages/addcomment.action
      • pages/doaddcomment.action

      on mode and captchaId

        1. page-labels-form.vm
          3 kB
        2. page-location-form.vm
          4 kB
        3. createblogpost-form.vm
          3 kB
        4. macros.vm
          123 kB
        5. wiki-textarea.vm
          27 kB

              cbroadfoot Chris Broadfoot [Atlassian]
              dave@atlassian.com dave (Inactive)
              Affected customers:
              0 This affects my team
              Watchers:
              0 Start watching this issue

                Created:
                Updated:
                Resolved: