Show filters
70 Total Results
Displaying 51-60 of 70
Sort by:
Attacker Value
Unknown
CVE-2018-13394
Disclosure Date: August 15, 2018 (last updated November 27, 2024)
The acceptAnswer resource in Atlassian Confluence Questions before version 2.6.6, the bundled version of Confluence Questions was updated to a fixed version in Confluence version 6.9.0, allows remote attackers to modify a comment into an answer via a Cross-site request forgery (CSRF) vulnerability.
0
Attacker Value
Unknown
CVE-2018-13393
Disclosure Date: August 15, 2018 (last updated November 27, 2024)
The convertCommentToAnswer resource in Atlassian Confluence Questions before version 2.6.6, the bundled version of Confluence Questions was updated to a fixed version in Confluence version 6.9.0, allows remote attackers to modify a comment into an answer via a Cross-site request forgery (CSRF) vulnerability.
0
Attacker Value
Unknown
CVE-2018-1999039
Disclosure Date: August 01, 2018 (last updated November 27, 2024)
A server-side request forgery vulnerability exists in Jenkins Confluence Publisher Plugin 2.0.1 and earlier in ConfluenceSite.java that allows attackers to have Jenkins submit login requests to an attacker-specified Confluence server URL with attacker specified credentials.
0
Attacker Value
Unknown
CVE-2018-13389
Disclosure Date: July 10, 2018 (last updated November 27, 2024)
The attachment resource in Atlassian Confluence before version 6.6.1 allows remote attackers to spoof web content in the Mozilla Firefox Browser through attachments that have a content-type of application/rdf+xml.
0
Attacker Value
Unknown
CVE-2017-18084
Disclosure Date: February 02, 2018 (last updated November 26, 2024)
The usermacros resource in Atlassian Confluence Server before version 6.3.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the description of a macro.
0
Attacker Value
Unknown
CVE-2017-18085
Disclosure Date: February 02, 2018 (last updated November 26, 2024)
The viewdefaultdecorator resource in Atlassian Confluence Server before version 6.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the key parameter.
0
Attacker Value
Unknown
CVE-2017-18083
Disclosure Date: February 02, 2018 (last updated November 26, 2024)
The editinword resource in Atlassian Confluence Server before version 6.4.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the contents of an uploaded file.
0
Attacker Value
Unknown
CVE-2017-18086
Disclosure Date: February 02, 2018 (last updated November 26, 2024)
Various resources in Atlassian Confluence Server before version 6.4.2 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the issuesURL parameter.
0
Attacker Value
Unknown
CVE-2017-16856
Disclosure Date: December 05, 2017 (last updated November 26, 2024)
The RSS Feed macro in Atlassian Confluence before version 6.5.2 allows remote attackers to inject arbitrary HTML or JavaScript via cross site scripting (XSS) vulnerabilities in various rss properties which were used as links without restriction on their scheme.
0
Attacker Value
Unknown
CVE-2017-9505
Disclosure Date: June 15, 2017 (last updated November 26, 2024)
Atlassian Confluence starting with 4.3.0 before 6.2.1 did not check if a user had permission to view a page when creating a workbox notification about new comments. An attacker who can login to Confluence could receive workbox notifications, which contain the content of comments, for comments added to a page after they started watching it even if they do not have permission to view the page itself.
0