Description
The viewdefaultdecorator resource in Atlassian Confluence Server before version 6.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the key parameter.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2020-2735 Vulnerability (CVE-2020-2735)
Apache read beyond bounds in mod_isapi Vulnerability (CVE-2022-28330)
WordPress Plugin DMCA WaterMarker Cross-Site Scripting (1.0)
Squid Out-of-bounds Read Vulnerability (CVE-2023-49285)
WordPress Plugin UserPro-Community and User Profile Multiple Vulnerabilities (5.1.4)