Description
The editinword resource in Atlassian Confluence Server before version 6.4.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the contents of an uploaded file.
Remediation
References
Related Vulnerabilities
WordPress Plugin Import all XML, CSV & TXT into WordPress Server-Side Request Forgery (6.5.2)
e107 Other Vulnerability (CVE-2010-0996)
WordPress Plugin Participants Database Multiple Vulnerabilities (1.7.5.3)
PostgreSQL Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-1901)
Apache Tomcat Uncontrolled Resource Consumption Vulnerability (CVE-2019-0199)