-
Type:
Bug
-
Resolution: Fixed
-
Priority:
High
-
Affects Version/s: 5.6.4, 5.7-m22, 5.6-OD-38-053
-
Component/s: Editor - Page / Comment Editor
-
6.5
NOTE: This bug report is for Confluence Server. Using Confluence Cloud? See the corresponding bug report.
- Create a parent page A with a child page B
- Add an {excerpt} macro to B containing the text <script>alert("Gotcha!");</script>
- Add the {children} macro to page A, with "Show excerpts" checked
- Alert is shown when viewing A
This is currently present on EAC - likely to be in released versions; not tested yet.
Found by dpabst and me during QA ![]()
- relates to
-
CONFCLOUD-35777 XSS vulnerability in "children" macro when displaying excerpts
-
- Closed
-
- mentioned in
-
Page Loading...