Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-8980

XSS vulnerability at "Edit Space Permissions"

    XMLWordPrintable

Details

    • Bug
    • Resolution: Fixed
    • High
    • 2.5.6, 2.6.0
    • 2.5.4
    • None
    • Standalone

    Description

      Description:
      XSS vulnerability at "Edit Space Permissions" page

      Exploit:
      Write to the "Grant permission to" field: "<script>alert(document.cookie)</script>"

      Attachments

        Activity

          People

            Unassigned Unassigned
            b1e07ee35f09 Gergely Hodicska
            Votes:
            1 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: