Description
Widget Connector addon of Confluence is vulnerable to path traversal and server side template injection, which could be used for remote code execution.
Remediation
Upgrade to the latest version of Confluence
References
Related Vulnerabilities
Barracuda networks products multiple directory traversal vulnerabilities
WooCommerce Multiple Vulnerabilities (6.2.0)
cloudsafe365_for_WP 'file' Parameter Remote File Disclosure (1.46)
Directory Traversal (lib/translation.functions.php) (CMS Made Simple) v1.6.x
Pulse Secure SSL VPN Arbitrary File reading (CVE-2019-11510)