-
Bug
-
Resolution: Fixed
-
High
-
2.6.2, 2.7.3, 2.8.2, 2.9.2
-
None
The filenames in the attachment list of the link popup aren't being escaped.
If you upload an attachment with a filename including html it could be executed.
[CONFSERVER-13717] Attachment list in popup doesn't escape filenames causing XSS hole
Workflow | Original: JAC Bug Workflow v3 [ 2894925 ] | New: CONFSERVER Bug Workflow v4 [ 2987305 ] |
Workflow | Original: JAC Bug Workflow v2 [ 2782214 ] | New: JAC Bug Workflow v3 [ 2894925 ] |
Status | Original: Resolved [ 5 ] | New: Closed [ 6 ] |
Workflow | Original: JAC Bug Workflow [ 2710680 ] | New: JAC Bug Workflow v2 [ 2782214 ] |
Workflow | Original: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2375996 ] | New: JAC Bug Workflow [ 2710680 ] |
Workflow | Original: Confluence Workflow - Public Facing - Restricted v5 [ 2263003 ] | New: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2375996 ] |
Workflow | Original: Confluence Workflow - Public Facing - Restricted v5.1 - TEMP [ 2212733 ] | New: Confluence Workflow - Public Facing - Restricted v5 [ 2263003 ] |
Workflow | Original: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2160429 ] | New: Confluence Workflow - Public Facing - Restricted v5.1 - TEMP [ 2212733 ] |
Workflow | Original: Confluence Workflow - Public Facing - Restricted v5 [ 1916340 ] | New: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2160429 ] |
Workflow | Original: Confluence Workflow - Public Facing - Restricted v3 [ 1721918 ] | New: Confluence Workflow - Public Facing - Restricted v5 [ 1916340 ] |
Workflow | Original: CONF Bug Subtask WF (TEMP) [ 1675017 ] | New: Confluence Workflow - Public Facing - Restricted v3 [ 1721918 ] |