-
Bug
-
Resolution: Fixed
-
Highest
-
2.5
CONF-16888 has introduced or re-introduced an XSS vulnerability.
To reproduce:
- Create a new user, and for the Full Name use:
<script>alert('Vulnerable')</script>
- Go to ../admin/indexbrowser.jsp and find the entry
- Click on the entry, and the script is executed.
This also happens for other content types.
- is caused by
-
CONFSERVER-16888 indexbrowser.jsp displays documents but links to details display nothing
-
- Closed
-
[CONFSERVER-17165] Links from indexbrowser.jsp are vulnerable to XSS attacks
Workflow | Original: JAC Bug Workflow v3 [ 2894414 ] | New: CONFSERVER Bug Workflow v4 [ 2986997 ] |
Workflow | Original: JAC Bug Workflow v2 [ 2778810 ] | New: JAC Bug Workflow v3 [ 2894414 ] |
Status | Original: Resolved [ 5 ] | New: Closed [ 6 ] |
Workflow | Original: JAC Bug Workflow [ 2718581 ] | New: JAC Bug Workflow v2 [ 2778810 ] |
Workflow | Original: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2382690 ] | New: JAC Bug Workflow [ 2718581 ] |
Workflow | Original: Confluence Workflow - Public Facing - Restricted v5 [ 2275713 ] | New: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2382690 ] |
Workflow | Original: Confluence Workflow - Public Facing - Restricted v5.1 - TEMP [ 2218329 ] | New: Confluence Workflow - Public Facing - Restricted v5 [ 2275713 ] |
Workflow | Original: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2172291 ] | New: Confluence Workflow - Public Facing - Restricted v5.1 - TEMP [ 2218329 ] |
Workflow | Original: Confluence Workflow - Public Facing - Restricted v5 [ 1934262 ] | New: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2172291 ] |
Workflow | Original: Confluence Workflow - Public Facing - Restricted v3 [ 1733817 ] | New: Confluence Workflow - Public Facing - Restricted v5 [ 1934262 ] |
Workflow | Original: CONF Bug Subtask WF (TEMP) [ 1692349 ] | New: Confluence Workflow - Public Facing - Restricted v3 [ 1733817 ] |