Details
-
Bug
-
Resolution: Fixed
-
Major
-
2.3.2, 2.4
-
None
-
security, xss, patch
-
Integration
-
Trivial
-
Description
Failed escaping test.
* Parameter: "replyto" Tested file: templates/commentsinline.vm URL: http://localhost:8080/xwiki/bin/view/Main/WebHome?skin=default&vm=commentsinline.vm&replyto=aaa%22bbb%27ccc%3Eddd%3Ceee&xpage=xpart&language=en List of validation errors: line 11 column 80 FATAL: Unescaped apostrophe character