Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-30802

execution of javascript from filename

    XMLWordPrintable

Details

    Description

      Steps to replicate:

      1. Add an attachment
      2. Rename the file to "<iframe onload=alert(1)>.txt"
      3. Copy its remove link and open the link in a new browser window
      4. Result: The JavaScript code is executed, rather than showing the "proceed w/ deletion" screen.

      Everything works normally if you just click the delete button rather than copying the link into a new tab.

      Attachments

        Issue Links

          Activity

            People

              igerges Issac Gerges (Inactive)
              9df2cd731499 Bernd Lindner
              Votes:
              0 Vote for this issue
              Watchers:
              7 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: