-
Type:
Bug
-
Resolution: Fixed
-
Priority:
Medium
-
Affects Version/s: 2.10.3
-
Component/s: None
-
Environment:
Server: QA-EAC 3.0-m9-r2
OS: Mac OS X 10.5.6
Browser: Safari 3.2.1 (5525.27.1)
A custom message can be used for when no contributors are found, it can be used as a XSS vector: https://qa-eac.atlassian.com/confluence/display/~pdzwart/Contributors+Macro+noneFoundMessage+XSS
Markup
{contributors:noneFoundMessage=<iframe src="http://www.youtube.com/v/60og9gwKh1o&hl=en&fs=1&autoplay=1"></iframe>}

- is cloned from
-
CONFSERVER-15397 Instant Messenger Macro XSS Vector
-
- Closed
-