Uploaded image for project: 'Confluence Server and Data Center'
  1. Confluence Server and Data Center
  2. CONFSERVER-17165

Links from indexbrowser.jsp are vulnerable to XSS attacks

    XMLWordPrintable

Details

    Description

      CONF-16888 has introduced or re-introduced an XSS vulnerability.

      To reproduce:

      • Create a new user, and for the Full Name use:
        <script>alert('Vulnerable')</script>
      • Go to ../admin/indexbrowser.jsp and find the entry
      • Click on the entry, and the script is executed.

      This also happens for other content types.

      Attachments

        1. viewdocument.jsp
          2 kB
          Anatoli

        Issue Links

          Activity

            People

              akazatchkov Anatoli
              mhrynczak Mark Hrynczak (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: