-
Type:
Bug
-
Resolution: Fixed
-
Priority:
Low
-
Component/s: Integrations - Confluence Questions
-
Severity 3 - Minor
NOTE: This bug report is for Confluence Cloud. Using Confluence Server? See the corresponding bug report.
We have received an external report of a dom xss in the moderation code for a question on answers.atlassian.com.
1) DOM XSS
Go to https://answers.atlassian.com/
Prepare an question ,after savin it go to the question ,there is an option of "Moderate" ,click it ,there is an option to "Create bounty" select that , and in the input box which appears enter
'"><iframe/onload=prompt(document.cookie);>
and press ok and alert will come immediately !!
This issue would require some social engineering exploit through perhaps clickjacking and tricking a user into XSS'ing themselves on answers.atlassian.com.
- is related to
-
CONFSERVER-47423 'self' xss reported in a question's moderate
-
- Closed
-
- relates to
-
CONFCLOUD-46839 "Cannot vote your own post" message contains escaped html
-
- Closed
-
-
CONFCLOUD-47347 Escaped HTML in Message When Voting on Own Post
-
- Closed
-