Skip to main content
Nintex Community Menu Bar

Code Fix: Stored XSS vulnerability in out of office exception rule form

  • May 14, 2026
  • 0 replies
  • 8 views

Forum|alt.badge.img+9

Issue Description

When you use the Out of Office function in the Worklist Control and configure an Out of Office exception rule, a stored XSS vulnerability can be triggered in the exception rule form.

Resolution

The fix is available in:

  1. Ensure you have the correct K2 version and/or Cumulative update installed. See KB001893 to see what Fix Pack level you have installed.
  2. Download the latest Fix Pack using the links in the table above for the version you require.
  3. Install the Fix Pack to apply the fix.
  4. It is recommended to clear browser cache and refresh the page.