Description
Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in user macro parameters. The affected versions are before version 7.4.2, and from version 7.5.0 before 7.5.2.
Remediation
References
Related Vulnerabilities
MediaWiki CVE-2023-45362 Vulnerability (CVE-2023-45362)
IBM WebSEAL Improper Restriction of Rendered UI Layers or Frames Vulnerability (CVE-2018-1803)
WordPress Plugin Woocommerce Aliexpress Dropshipping Lite PHP Object Injection (1.0.1)
Oracle JRE CVE-2013-5849 Vulnerability (CVE-2013-5849)
WordPress Plugin Newsletter Manager PHP Object Injection (1.5.1)