Uploaded image for project: 'XWiki Platform'
  1. XWiki Platform
  2. XWIKI-5235

Reflected XSS over section parameter

    XMLWordPrintable

Details

    • Bug
    • Resolution: Duplicate
    • Major
    • None
    • 2.2.6, 2.3.1, 2.4 M1
    • None
    • security, xss
    • Integration
    • Trivial

    Description

      Reported by the Dutch security audit. Example:

      http://localhost:8080/xwiki/bin/view/Main/Copy?xpage=edit&editor=wysiwyg&section=%22%3E%3Cscript%3Ealert%281%29%3C%2Fscript%3E
      

      Attachments

        Issue Links

          Activity

            People

              nickless Alex Busenius
              nickless Alex Busenius
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: