[XSS][USERNAME] - XSS issue occurs if filtering for a user with the "><img src=x onerror=alert(1)>"
Description
Java script is executed when filtering for a user with "><img src=x onerror=alert(1)>” .
Steps to reproduce
-
Create an external share link
-
Navigate to your Atlassian profile or Click here
-
Add "><img src=x onerror=alert(1)> to your name field
-
Return to confluence and navigate to External Share Space settings (Side panel)
-
On creator field, look for your username
Similar issue occurred on Approval path for confluence - reported on Bug Crowd - APFC issue
Actual result
User will be prompt with java script error
Expected result
No java script is executed
Issue occurs on both QA and Production builds
Activity
Show:
Create issue
Done
Add watchers
Details
Priority
Created
16 August 2022, 13:42
Updated
15 November 2024, 15:54
Created: 16 August 2022, 11:42
Updated:
15 November 2024, 14:54
@Kamil Zarychta Fix verified on QA environment.
@Parsa Shiva fix deployed on QA, could you verify it ?
@Parsa Shiva
🚀