Uploaded image for project: 'XWiki Platform'
  1. XWiki Platform
  2. XWIKI-5442

XSS in rename.vm

    XMLWordPrintable

Details

    • security, xss
    • Integration
    • Trivial

    Description

      Injection over space and page name under the following conditions:

      1. Attempt to rename an existing document into a "bad" document (containing script in space or page name)
      2. Rename existing "bad" document into something else
      3. Rename existing document into a "bad" document

      Attachments

        Activity

          People

            nickless Alex Busenius
            nickless Alex Busenius
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: