Uploaded image for project: 'Confluence Data Center'
  1. Confluence Data Center
  2. CONFSERVER-54903

XSS in the editinword resource through the contents of an uploaded file - CVE-2017-18083

      The editinword resource in Atlassian Confluence Server before version 6.4.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the contents of an uploaded file.

            [CONFSERVER-54903] XSS in the editinword resource through the contents of an uploaded file - CVE-2017-18083

            Katherine Yabut made changes -
            Workflow Original: JAC Bug Workflow v3 [ 2885287 ] New: CONFSERVER Bug Workflow v4 [ 2996027 ]
            Owen made changes -
            Workflow Original: JAC Bug Workflow v2 [ 2790718 ] New: JAC Bug Workflow v3 [ 2885287 ]
            Status Original: Resolved [ 5 ] New: Closed [ 6 ]
            Owen made changes -
            Workflow Original: JAC Bug Workflow [ 2737140 ] New: JAC Bug Workflow v2 [ 2790718 ]
            Owen made changes -
            Symptom Severity Original: Major [ 14431 ] New: Severity 2 - Major [ 15831 ]
            Owen made changes -
            Workflow Original: Confluence Workflow - Public Facing - Restricted v5 - TEMP [ 2594759 ] New: JAC Bug Workflow [ 2737140 ]
            David Black made changes -
            Labels Original: advisory advisory-to-release bugbounty cvss-medium loyalty security sxss xss New: advisory advisory-released bugbounty cvss-medium loyalty security sxss xss
            David Black made changes -
            Security Original: Atlassian Staff [ 10750 ]
            David Black made changes -
            Priority Original: Low [ 4 ] New: Medium [ 3 ]
            David Black made changes -
            Summary Original: Sanitised security issue 00a46a85e90a43d5125f3325eebf3df920078955b1ba61f9ce1579fc0e1a2a34 New: XSS in the editinword resource through the contents of an uploaded file - CVE-2017-18083
            David Black made changes -
            Description Original: Component in Atlassian Confluence Server from version 6.2.4 before version 6.4.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in VULN_INFO. New: The editinword resource in Atlassian Confluence Server before version 6.4.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the contents of an uploaded file.

              Unassigned Unassigned
              security-metrics-bot Security Metrics Bot
              Affected customers:
              0 This affects my team
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: