• Open the Create dialog
      • Select "Share a Link" article
      • In the 'Topics' field, enter an attack string such as:
        <script>alert("hello")</script>

      =>The script will be executed

            [CONFSERVER-31893] XSS vulnerability in 'Share a link' blueprint

            Katherine Yabut made changes -
            Workflow Original: JAC Bug Workflow v3 [ 2879191 ] New: CONFSERVER Bug Workflow v4 [ 2987742 ]
            Owen made changes -
            Workflow Original: JAC Bug Workflow v2 [ 2783476 ] New: JAC Bug Workflow v3 [ 2879191 ]
            Status Original: Resolved [ 5 ] New: Closed [ 6 ]
            Owen made changes -
            Workflow Original: JAC Bug Workflow [ 2711533 ] New: JAC Bug Workflow v2 [ 2783476 ]
            Owen made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2376960 ] New: JAC Bug Workflow [ 2711533 ]
            Katherine Yabut made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v5 [ 2264972 ] New: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2376960 ]
            Katherine Yabut made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v5.1 - TEMP [ 2213632 ] New: Confluence Workflow - Public Facing - Restricted v5 [ 2264972 ]
            Katherine Yabut made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2162609 ] New: Confluence Workflow - Public Facing - Restricted v5.1 - TEMP [ 2213632 ]
            Katherine Yabut made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v5 [ 1949825 ] New: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2162609 ]
            Katherine Yabut made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v3 [ 1743834 ] New: Confluence Workflow - Public Facing - Restricted v5 [ 1949825 ]
            Katherine Yabut made changes -
            Workflow Original: CONF Bug Subtask WF (TEMP) [ 1705203 ] New: Confluence Workflow - Public Facing - Restricted v3 [ 1743834 ]

              tvuu Tin Vuu (Inactive)
              phucnguyen Phuc Thi Minh Nguyen
              Affected customers:
              0 This affects my team
              Watchers:
              4 Start watching this issue

                Created:
                Updated:
                Resolved: