Details
-
Bug
-
Resolution: Fixed
-
Major
-
2.2.3, 2.3, 2.4 M1
-
None
-
security, xss, patch
-
Integration
-
Unknown
-
Description
It is possible to inject JavaScript at several places (at least 1 in JavaScript and 2 in HTML) when passing a script as the "editor" parameter. Example:
http://localhost:8080/xwiki/bin/edit/Main/WebHome?&editor=%22;%20alert%28%22js%22%29;%2F%2F%3E%3Cscript%3Ealert%28%22html%22%29%3C%2Fscript%3E