Description
Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.8.17 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to rest/prototype/1/session/check.
Remediation
References
Related Vulnerabilities
Nexus Repository Manager Cleartext Storage of Sensitive Information Vulnerability (CVE-2020-11415)
Atlassian Jira Server-Side Request Forgery (SSRF) Vulnerability (CVE-2019-20408)
OpenSSL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-3195)
WordPress 3.7.x Cross-Domain Flash Injection Vulnerability (3.7 - 3.7.24)
Oracle Database Server CVE-2023-22052 Vulnerability (CVE-2023-22052)