-
Bug
-
Resolution: Fixed
-
Highest
-
2.10
Use the following markup on a page:
text
{noformat}><script>alert('XSS')</script><b a=a{noformat}
On another page in the same space, use the
{index}macro. When this page is loaded by a user, the script will run.
See here for a working example on QA-CAC.
- is duplicated by
-
CONFSERVER-6990 Javascript in wiki page executed by {index}
-
- Closed
-
We won't be able to get to a newer version of Confluence until later in the summer. Would it be possible to backup this fix to advanced macros version 1.3? I suspect that a lot of folks are still running Confluence 2.8.x.
best,
Mark