Uploaded image for project: 'Confluence Cloud'
  1. Confluence Cloud
  2. CONFCLOUD-54163

CSRF in doremoveblogpost.action

    XMLWordPrintable

Details

    Description

      Any page can be deleted if a user with sufficient privileges to delete the page clicks an attacker controlled link, or views an image at an attack controller URL.

      /pages/doremoveblogpost.action?pageId=<page to delete>

      Attachments

        Activity

          People

            djohnson@atlassian.com Dougall Johnson
            djohnson@atlassian.com Dougall Johnson
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: