Description
The usermacros resource in Atlassian Confluence Server before version 6.3.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the description of a macro.
Remediation
References
Related Vulnerabilities
Oracle JRE CVE-2018-2790 Vulnerability (CVE-2018-2790)
Oracle JRE CVE-2020-2816 Vulnerability (CVE-2020-2816)
WordPress Plugin Blogomatic Cross-Site Scripting (1.0)
WordPress Plugin eShop Multiple Vulnerabilities (6.3.14)
Apache Traffic Server Improper Input Validation Vulnerability (CVE-2022-31778)