Details
-
Bug
-
Resolution: Fixed
-
Major
-
2.3, 2.2.6, 2.4
-
None
-
security, xss, sql injection, patch
-
Integration
-
Trivial
-
Description
HQL injection over "text" parameter:
http://localhost:8080/xwiki/bin/view/Main/WebHome?xpage=browsewysiwyg&text=%27buh
XSS over space:
http://localhost:8080/xwiki/bin/view/"><script>alert(1)<%2Fscript><div+id%3D"/WebHome?xpage=browsewysiwyg