From: OFFCONN-81:

      Using "office excel"-macro (as part of viewfile, which is part of office connector plugin) seems to open up the possibility to get injected with XSS-code.

      Steps to reproduce:

      1.) Create an excel-file with following content in one cell:

      '"><script>alert('XSS')</script><
      

      2.) Attach this file to a confluence page

      3.) Go into edit mode

      4.) Use the "office excel" macro and choose the excel file

      5.) Click "save"

      Result:

      An XSS-message appears

          Form Name

            [CONFSERVER-25909] XSS vulnerability in Office Connector plugin

            Katherine Yabut made changes -
            Workflow Original: JAC Bug Workflow v3 [ 2888960 ] New: CONFSERVER Bug Workflow v4 [ 2999948 ]
            Owen made changes -
            Workflow Original: JAC Bug Workflow v2 [ 2799685 ] New: JAC Bug Workflow v3 [ 2888960 ]
            Status Original: Resolved [ 5 ] New: Closed [ 6 ]
            Owen made changes -
            Workflow Original: JAC Bug Workflow [ 2730141 ] New: JAC Bug Workflow v2 [ 2799685 ]
            Owen made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2376124 ] New: JAC Bug Workflow [ 2730141 ]
            Katherine Yabut made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v5 [ 2263269 ] New: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2376124 ]
            Katherine Yabut made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v5.1 - TEMP [ 2212850 ] New: Confluence Workflow - Public Facing - Restricted v5 [ 2263269 ]
            Katherine Yabut made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2160764 ] New: Confluence Workflow - Public Facing - Restricted v5.1 - TEMP [ 2212850 ]
            Katherine Yabut made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v5 [ 1946661 ] New: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2160764 ]
            Katherine Yabut made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v3 [ 1742380 ] New: Confluence Workflow - Public Facing - Restricted v5 [ 1946661 ]
            Katherine Yabut made changes -
            Workflow Original: CONF Bug Subtask WF (TEMP) [ 1703173 ] New: Confluence Workflow - Public Facing - Restricted v3 [ 1742380 ]

              nbhawnani Niraj Bhawnani
              4022a846e2fa Kai Gottschalk
              Affected customers:
              1 This affects my team
              Watchers:
              4 Start watching this issue

                Created:
                Updated:
                Resolved: