Details
-
Bug
-
Resolution: Duplicate
-
Major
-
None
-
2.2.6, 2.3.1, 2.4 M1
-
None
-
security, xss
-
Integration
-
Trivial
-
Description
Reported by the Dutch security audit. Example:
http://localhost:8080/xwiki/bin/view/Main/Copy?xpage=edit&editor=wysiwyg§ion=%22%3E%3Cscript%3Ealert%281%29%3C%2Fscript%3E
Attachments
Issue Links
- duplicates
-
XWIKI-5243 Reflected XSS in edit(wiki|wysiwyg|wysiwygnew).vm
- Closed