-
Type:
Bug
-
Resolution: Fixed
-
Priority:
High
-
Affects Version/s: 2.5.4
-
Component/s: None
-
Environment:
Standalone
Description:
XSS via the "startsWith" field in pages/listpages-alphaview.action.
Exploit:
http://app/pages/listpages-alphaview.action?key=&startsWith=xss:<script>alert(document.cookie)</script>
- is cloned from
-
CONFSERVER-8950 XSS vulnerability in app/spaces/listattachmentforspace.action
-
- Closed
-