Uploaded image for project: 'XWiki Platform'
  1. XWiki Platform
  2. XWIKI-4819

XSS hole in edit comments / version history.

    XMLWordPrintable

Details

    • Integration
    • Trivial

    Description

      test case:
      log in, edit a page, in the edit comment write:
      <script>alert("A Hole!")</script>
      save,
      every time the history of that page is viewed, the alert is shown.

      I think the only place which requires fixing is historyinline.vm

      Attachments

        Activity

          People

            sdumitriu Sergiu Dumitriu
            calebjamesdelisle CalebJamesDeLisle
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: