NOTE: This bug report is for Confluence Server. Using Confluence Cloud? See the corresponding bug report.

      Luke Jahnke of the Australia Post Digital Mailbox Security Team reported to Atlassian an XSS in nesting various markup.

            [CONFSERVER-51825] XSS Vulnerability in wiki markup

            CVSS score: 5.5 => Medium severity

            Exploitability Metrics

            AccessVector Network
            AccessComplexity Low
            Authentication Single

            Impact Metrics

            ConfImpact Partial
            IntegImpact Partial
            AvailImpact None

            David Black added a comment - CVSS score: 5.5 => Medium severity Exploitability Metrics AccessVector Network AccessComplexity Low Authentication Single Impact Metrics ConfImpact Partial IntegImpact Partial AvailImpact None

              Unassigned Unassigned
              ca3d894a75c2 Luke Jahnke
              Affected customers:
              0 This affects my team
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: