Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-15883

XSS in concurrent edit notification

    XMLWordPrintable

Details

    • Bug
    • Resolution: Fixed
    • Medium
    • 3.0-rc1
    • 3.0-beta3
    • None

    Description

      If a page is being editted by

      <script>alert('hacked')</script>
      

      and another user edits it at the same time, they are vulnerable to a potential XSS attack.

      Attachments

        Activity

          People

            cmiller CharlesA
            alynch Andrew Lynch (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: