Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-15440

XSS vulnerability can be exploited with the contentbylabel macro

      Use markup:

      {contentbylabel:labels=foo|title=<script>alert('Vulnerable')</script>}

      The script will be executed when the page is viewed.

            [CONFSERVER-15440] XSS vulnerability can be exploited with the contentbylabel macro

            Confluence 2.10.x users can install the attached plugin jar (version 1.5.3.5) to fix this issue.

            David Taylor (Inactive) added a comment - Confluence 2.10.x users can install the attached plugin jar (version 1.5.3.5) to fix this issue.

            David Taylor (Inactive) added a comment - - edited

            I have tested version 1.6.4 on Confluence 3.0.1 and it works correctly. Anyone on 3.0.x should be able to upgrade the plugin to fix this issue.

            David Taylor (Inactive) added a comment - - edited I have tested version 1.6.4 on Confluence 3.0.1 and it works correctly. Anyone on 3.0.x should be able to upgrade the plugin to fix this issue.

            To fix this bug please upgrade confluence-advanced-macros to 1.6.4.

            Ryan Ericson [Atlassian] added a comment - To fix this bug please upgrade confluence-advanced-macros to 1.6.4.

            the corresponding issue in the plugin project: http://developer.atlassian.com/jira/browse/ADVMACROS-126

            Ryan Ericson [Atlassian] added a comment - the corresponding issue in the plugin project: http://developer.atlassian.com/jira/browse/ADVMACROS-126

              Unassigned Unassigned
              mhrynczak Mark Hrynczak (Inactive)
              Affected customers:
              0 This affects my team
              Watchers:
              0 Start watching this issue

                Created:
                Updated:
                Resolved: