Uploaded image for project: 'XWiki Platform'
  1. XWiki Platform
  2. XWIKI-12744

Cross-Site Scripting (XSS) Vulnerability in Activity Stream for Tags

    XMLWordPrintable

Details

    • Unknown
    • N/A
    • N/A

    Description

      It is possible to construct a Tags-URL, which exploits a XSS-Vulnerability:

      www.xwiki.org/xwiki/bin/view/Main/Tags?do=viewTag&tag=%3Cscript%3Ealert(%27hello%27)%3B%3C%2Fscript%3E

      Attachments

        Activity

          People

            camil7 Clemens Robbenhaar
            pheyn Peter Heyn
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: