Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-26221

XSS vulnerability in the "import word document" page action through the page name

    XMLWordPrintable

Details

    Description

      On the "import word document" page action the name of the confluence page is a persistent xss vector (as it is not encoded).

      How to Reproduce:

      1. Create a confluence page with the following title

      XSS"/><script>alert('XSS')</script>
      

      2. Navigate to the created page
      3. Under the tools menu select "Import Word Document"
      4. Upload a word document
      5. Click "Next"
      6. See an alert prompt containing the text 'XSS' within it.

      Attachments

        Issue Links

          Activity

            People

              jxie Chii
              dblack David Black
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: