Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-25013

Autocomplete: XSS vulnerability

    XMLWordPrintable

Details

    Description

      Edit a page with the following markup:

      <script>alert('xxxxxxxxss')</script>

      1. Highlight the text, and press Ctrl+Shift+K
      2. Select "insert link into page"
      3. note that the script is executed.

      Attachments

        Activity

          People

            shaffenden Steve Haffenden (Inactive)
            dblack David Black
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: