Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-11985

XSS vulnerability in create/edit/copy page and blogpost actions

    • Icon: Bug Bug
    • Resolution: Fixed
    • Icon: Highest Highest
    • 2.8.2
    • 2.8
    • None

      The following create/edit page URL's are vulnerable:

      • /pages/createpage.action
      • /pages/docreatepage.action
      • /pages/editpage.action
      • /pages/doeditepage.action

      on parentPageString

      Example of a maliciously crafted path:
      /pages/doeditpage.action?pageId=12345&parentPageString=Home%22%3e%3cscript%3ealert("XSS")%3c%2fscript%3e

      where 12345 is a valid page id.

      Patch instructions for 2.8.x

      1. Shut down Confluence
      2. Copy attached content-editor.vm to confluence/template/custom
      3. Start up Confluence

            [CONFSERVER-11985] XSS vulnerability in create/edit/copy page and blogpost actions

            Don Willis added a comment -

            Note that on pre 2.8 versions of Confluence, this is fixed by the page-location-form.vm attached to CONF-11027, and is fixed in 2.7.3

            Don Willis added a comment - Note that on pre 2.8 versions of Confluence, this is fixed by the page-location-form.vm attached to CONF-11027 , and is fixed in 2.7.3

              don.willis@atlassian.com Don Willis
              james.rinker James Rinker
              Affected customers:
              0 This affects my team
              Watchers:
              0 Start watching this issue

                Created:
                Updated:
                Resolved: