Description
Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.10.6 allows remote attackers to inject arbitrary web script or HTML via the newFileName parameter to pages/doeditattachment.action.
Remediation
References
Related Vulnerabilities
Atlassian Jira Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2020-14174)
IBM RTC Exposure of Resource to Wrong Sphere Vulnerability (CVE-2020-4989)
WordPress Plugin Posts in Page Local File Inclusion (1.2.4)
WordPress Plugin WP Socializer-Simple & Easy Social Media Share Icons Cross-Site Scripting (2.4.2)