Uploaded image for project: 'camunda BPM'
  1. camunda BPM
  2. CAM-4481

Task List: Javascript in task comments security issue

XMLWordPrintable

      Scripts in task comments

      <script>window.alert("sometext");</script>
      

      will actually execute when viewed in history.

      Recreate (in task list):
      1. Use 'Create task' to create and assign task to mary
      2. As mary, use 'Add Comment', type in script text

      and so mary can execute scripts for demo by

      3. Reassign to demo
      4. As demo, view in history

        This is the controller panel for Smart Panels app

              michael.schoettes Michael Schoettes
              skjolber Thomas Skjolberg
              Votes:
              1 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated:
                Resolved: