Description
1. Create a new space named "<script>alert('xss')</script>"
2. Open the space index for the new space and the javascript will be executed from the livetable's 'Space' column.
As reported on http://www.exploit-db.com/exploits/20856/
Attachments
Issue Links
- relates to
-
XWIKI-9336 Quotes are escaped in doc.title livetable column
- Closed
-
XWIKI-9289 HTML code display instead of User details in Livetable containing User column
- Closed
-
XWIKI-9493 List of wikis livetable has issue with some characters
- Closed
- links to