-
Bug
-
Resolution: Fixed
-
Medium
-
3.0
-
None
A user with username "><script>alert("foo")</script> that is linked to via [~username] markup results in script being executed.
Curiously, viewing the space homepage of that user results in a blank page.
This of course is prevented for public signup, but if the user gets created via other means, i.e. external user management, or via admin control panel then this is a valid point of attack
- is caused by
-
CONFSERVER-15945 Inconsistent validation of usernames between admin-added and public signup
-
- Closed
-
- relates to
-
CONFSERVER-15920 User Hover is not working for a username which contains plus characters
-
- Closed
-
If you are not in a position to upgrade to Confluence 3.0.1, you can patch your existing Confluence 3.0.0 instance to fix this XSS issue using the attached zip file.
To apply the patch:
(Create the appropriate folder(s) if they do not exist.)