Uploaded image for project: 'camunda BPM'
  1. camunda BPM
  2. CAM-4481

Task List: Javascript in task comments security issue

    XMLWordPrintable

Details

    Description

      Scripts in task comments

      <script>window.alert("sometext");</script>
      

      will actually execute when viewed in history.

      Recreate (in task list):
      1. Use 'Create task' to create and assign task to mary
      2. As mary, use 'Add Comment', type in script text

      and so mary can execute scripts for demo by

      3. Reassign to demo
      4. As demo, view in history

      mgm-controller-panel

        This is the controller panel for Smart Panels app

        Attachments

          Activity

            People

              michael.schoettes Michael Schoettes
              skjolber Thomas Skjolberg
              Votes:
              1 Vote for this issue
              Watchers:
              4 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Salesforce