Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-31015

Doconfiguretheme action accessible to non-administrative users

    XMLWordPrintable

Details

    Description

      The doconfiguretheme action allows for configuration of the Documentation theme for Confluence. This action is defined in two namespaces, one of which is accessible by any user of Confluence (including anonymous users, if anonymous use of Confluence is allowed). If this action is executed with no space specified, it is applied to all spaces that have not already configured the Documentation theme without any access checks.

      The doconfiguretheme action can be accessed by a user using the form at:

      /spaces/doctheme/configuretheme.action?key=spacekey

      If the "key" parameter is removed, the submitted form will demonstrate the vulnerability.

      Attachments

        Issue Links

          Activity

            People

              psaw PatrickA
              a136c65a63df Phillip Langlois
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: