Uploaded image for project: 'XWiki Platform'
  1. XWiki Platform
  2. XWIKI-15205

Reflected XSS vulnerability in the livetable

    XMLWordPrintable

Details

    • Low
    • Hard
    • N/A
    • N/A

    Description

      There is a reflected xss vulnerability because of unfiltered response values.

      All input values (GET/URL parameters) are responded unfiltered.
      Although the browser does not interpret potential harmful JS code, it could be used in complex attacks.

      Is there already a solution?

      Attachments

        1. wiki-s4-request.png
          22 kB
          Laura Volmari
        2. wiki-s4-response_02.png
          153 kB
          Laura Volmari

        Issue Links

          Activity

            People

              MichaelHamann Michael Hamann
              LaVolm Laura Volmari
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: