-
Bug
-
Resolution: Fixed
-
High
-
None
-
Server: QA-EAC 3.0-m9-r2
OS: Mac OS X 10.5.6
Browser: Safari 3.2.1 (5525.27.1)
The title of the gallery can be used as an XSS vector:
https://qa-eac.atlassian.com/confluence/display/~pdzwart/Gallery+Macro+XSS+Test
Form Name |
---|
To fix this issue in version 2.9.x of Confluence you will need to upgrade to version 1.4.2.2 of the Confluence Advanced Macros. The JAR file can be downloaded directly from here or you can upgrade using the Atlassian Plugin Repository client built into Confluence.