Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-8956

stored XSS vulnerability in app/themes/leftnavigation/configuretheme.action

      Description:
      Stored XSS via page app/themes/leftnavigation/configuretheme.action?key=~<USERNAME>

      Exploit:
      Example value in the Naviagtion Page field: "><script>aletr(document.cookie)</script><x x="

            [CONFSERVER-8956] stored XSS vulnerability in app/themes/leftnavigation/configuretheme.action

            Katherine Yabut made changes -
            Workflow Original: JAC Bug Workflow v3 [ 2891304 ] New: CONFSERVER Bug Workflow v4 [ 2983412 ]
            Owen made changes -
            Workflow Original: JAC Bug Workflow v2 [ 2781015 ] New: JAC Bug Workflow v3 [ 2891304 ]
            Status Original: Resolved [ 5 ] New: Closed [ 6 ]
            Owen made changes -
            Workflow Original: JAC Bug Workflow [ 2711561 ] New: JAC Bug Workflow v2 [ 2781015 ]
            Owen made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2376994 ] New: JAC Bug Workflow [ 2711561 ]
            Katherine Yabut made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v5 [ 2265047 ] New: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2376994 ]
            Katherine Yabut made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v5.1 - TEMP [ 2213670 ] New: Confluence Workflow - Public Facing - Restricted v5 [ 2265047 ]
            Katherine Yabut made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2162684 ] New: Confluence Workflow - Public Facing - Restricted v5.1 - TEMP [ 2213670 ]
            Katherine Yabut made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v5 [ 1918984 ] New: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2162684 ]
            Katherine Yabut made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v3 [ 1723405 ] New: Confluence Workflow - Public Facing - Restricted v5 [ 1918984 ]
            Katherine Yabut made changes -
            Workflow Original: CONF Bug Subtask WF (TEMP) [ 1677471 ] New: Confluence Workflow - Public Facing - Restricted v3 [ 1723405 ]

              sleberrigaud Samuel Le Berrigaud
              b1e07ee35f09 Gergely Hodicska
              Affected customers:
              3 This affects my team
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: