Description
The RSS Feed macro in Atlassian Confluence before version 6.5.2 allows remote attackers to inject arbitrary HTML or JavaScript via cross site scripting (XSS) vulnerabilities in various rss properties which were used as links without restriction on their scheme.
Remediation
References
Related Vulnerabilities
WordPress Plugin Custom Contact Forms Security Bypass (5.1.0.3)
WordPress Plugin 3D Tag Cloud Cross-Site Request Forgery (3.8)
WordPress Plugin Conditional Marketing Mailer for WooCommerce Cross-Site Request Forgery (1.5.2)
Jboss EAP Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2010-3878)
WordPress Cross-Domain Flash Injection Vulnerability (0.70 - 3.6.1)