Details
-
Bug
-
Resolution: Cannot Reproduce
-
Critical
-
None
-
3.0
-
xss activity stream user status
-
Unknown
-
Description
User statuses and User messages allow HTML comment.
This also allows JavaScript that is extremely dangerous.
It also allows to target a specific user, a group of users or all the users of a wiki.
Tested and reproducible starting with XWiki 3.0.
Attachments
Issue Links
- relates to
-
XWIKI-6740 PR leak in Activity Stream
- Closed