[
https://issues.apache.org/jira/browse/JSPWIKI-1108?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Juan Pablo Santos RodrÃguez closed JSPWIKI-1108.
------------------------------------------------
Resolution: Fixed
> interwiki links with illegal characters causes XSS vulnerability
> ----------------------------------------------------------------
>
> Key: JSPWIKI-1108
> URL: https://issues.apache.org/jira/browse/JSPWIKI-1108
> Project: JSPWiki
> Issue Type: Improvement
> Components: Core & storage
> Reporter: brushed
> Priority: Minor
> Fix For: 2.11.0-M4
>
>
> Create a inter wiki link with the text
> {{[<script>alert`1`</script>://test.com]}}.
> You get an interwiki reference error, but also JS popup during edit(preview)
> and after saving the page.
--
This message was sent by Atlassian JIRA
(v7.6.3#76005)