Details
-
Bug
-
Resolution: Duplicate
-
Major
-
None
-
2.2 RC1
-
security, xss
-
Unknown
-
Description
Any registered user with "View" rights only is still able to use HTML-related features of Wiki Syntax ({{html} }, (% style="..." %) etc.) in all fields of the profile (including first/last name, company, phone...).
This can be used to create a profile worm that will be executed whenever the profile is viewed by another user (with possibly higher privileges).
Attachments
Issue Links
- duplicates
-
XWIKI-8592 XSS in the user profile
- Closed