Lucene search

K
atlassianSecurity-metrics-botATLASSIAN:CONFSERVER-54904
HistoryFeb 02, 2018 - 12:11 a.m.

XSS in the usermacros resource through the description of a macro - CVE-2017-18084

2018-02-0200:11:26
security-metrics-bot
jira.atlassian.com
51

EPSS

0.001

Percentile

28.6%

The usermacros resource in Atlassian Confluence Server before version 6.3.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the description of a macro.

Acknowledgements
Atlassian would like to credit Veit Hailperin (@fenceposterror) for reporting this issue to us.

EPSS

0.001

Percentile

28.6%

Related for ATLASSIAN:CONFSERVER-54904