Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-4825

Search results page needs to XML encode the query string provided by the user.

      We have had reports that the search query string is not correctly XML Encoded before being redisplayed to the user.

        1. searchresults.vmd.1.4
          3 kB
        2. searchresults.vmd.2.0
          2 kB
        3. searchsite-results.vm.1.4
          6 kB
        4. searchsite-results.vm.2.0
          7 kB

            [CONFSERVER-4825] Search results page needs to XML encode the query string provided by the user.

            Fixed the template files, surrounded the $queryString references with $generalUtil.escapeXml(....);

            Daniel Ostermeier added a comment - Fixed the template files, surrounded the $queryString references with $generalUtil.escapeXml(....);

            These versions of the files are for Confluence 1.4 instances. Please follow the same installation instructions as for the Cofluence 2.0 patch files.

            Daniel Ostermeier added a comment - These versions of the files are for Confluence 1.4 instances. Please follow the same installation instructions as for the Cofluence 2.0 patch files.

            These are the patched files for the 2.0 and 2.0.1 installations. These fixes are shipped with 2.0.2. To install these patches, please place these files in the following locations (replacing the original copies):

            WEBAPP_ROOT/decorators/components/searchresults.vmd
            WEBAPP_ROOT/search/searchsite-results.vm

            When you copy these files into your Confluence installation, please remove the .2.0 suffix.

            Before installing, remember to make a backup of the original files.

            Daniel Ostermeier added a comment - These are the patched files for the 2.0 and 2.0.1 installations. These fixes are shipped with 2.0.2. To install these patches, please place these files in the following locations (replacing the original copies): WEBAPP_ROOT/decorators/components/searchresults.vmd WEBAPP_ROOT/search/searchsite-results.vm When you copy these files into your Confluence installation, please remove the .2.0 suffix. Before installing, remember to make a backup of the original files.

            Fix this and provide patch files for 1.4.x and 2.0.x releases.

            Daniel Ostermeier added a comment - Fix this and provide patch files for 1.4.x and 2.0.x releases.

              Unassigned Unassigned
              8873c89cc788 Daniel Ostermeier
              Affected customers:
              0 This affects my team
              Watchers:
              0 Start watching this issue

                Created:
                Updated:
                Resolved: