vendor:
Confluence
by:
Jodson Santos
6,1
CVSS
MEDIUM
Cross-Site Scripting (XSS)
79
CWE
Product Name: Confluence
Affected Version From: 5.9.12
Affected Version To: 5.9.12
Patch Exists: YES
Related CWE: CVE-2016-6283
CPE: atlassian:confluence
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2016
Persisted Cross-Site Scripting (XSS) in Confluence Jira Software
Atlassian Confluence version 5.9.12 is vulnerable to persistent cross-site scripting (XSS) because it fails to securely validate user controlled data, thus making it possible for an attacker to supply crafted input in order to harm users. The bug occurs at pages carrying attached files, even though the attached file name parameter is correctly sanitized upon submission, it is possible for an attacker to later edit the attached file name property and supply crafted data (i.e HTML tags and script code) without the occurrence of any security checks, resulting in an exploitable persistent XSS.
Mitigation:
Upgrade to Confluence version 5.9.13 or later.