Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-37393

Attachments with invalid characters breaks attachment downloading/rendering

    XMLWordPrintable

Details

    Description

      Upload or rename an existing attachment with a name like "\.png" or "';alert(666)//\';alert(666)//";alert(666)//\";alert(666)//--></SCRIPT>">'><SCRIPT>alert(666)</SCRIPT>
      '"><script>alert(666)</script>.png"

      The attachment will not download (<base url>/download/attachments/<page id>/%5C.png will return 400) so it won't display or work on any macro, etc

      Attachments

        Activity

          People

            Unassigned Unassigned
            jsoderstrom Jonas Soderstrom (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: