Details
-
Bug
-
Resolution: Fixed
-
Major
-
4.2-milestone-2
-
Easy
-
N/A
-
N/A
-
Description
XSS possible in the user profile through the default fields:
- first_name
- last_name
- company
- phone
- blog
- blogfeed
For the email field I`ve also noticed that the inline edit form is affected if an html element is filled in at the end of the email.
As reported by http://www.exploit-db.com/exploits/20856/
Attachments
Issue Links
- is duplicated by
-
XWIKI-9073 Security Issue: An unprivileged user is allowed to use HTML/JavaScript in his/her profile
- Closed
- relates to
-
XWIKI-9652 Obfuscate e-mail address does not work anymore
- Closed
-
XWIKI-9653 User Picker doesn't display a correct value on the User Profile page in view mode
- Closed
-
XWIKI-9655 Links don't work any more in the comment and address user profile fields
- Closed
-
XWIKI-9658 XSS in the user profile
- Closed