Details
- 
    
Bug
 - 
    Resolution: Fixed
 - 
    
Blocker
 - 
    6.0-rc-1
 - 
    Windows 11 Pro, Firefox 110, using a local instance of XWiki 14.10.5 on MySQL 8, Tomcat 9.0.71
 
Description
Steps to reproduce
- Go to <server>xwiki/bin/get/FlamingoThemes/Cerulean?xpage=xpart&vm=delete.vm&xredirect=javascript:alert(document.domain)
 - Click 'Cancel' button
 
Expected results
No trigger should be displayed.
Actual results
A trigger confirmation dialog is displayed.
Attachments
Issue Links
- relates to
 - 
                    
XWIKI-20341 RXSS in Delete Template via redirect parameter
-         
 - Closed
 
 -