Atlassian

Confluence

19 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.16%
  • Veröffentlicht 02.02.2018 14:29:01
  • Zuletzt bearbeitet 21.11.2024 03:19:19

The editinword resource in Atlassian Confluence Server before version 6.4.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the contents of an uploaded file.

  • EPSS 0.19%
  • Veröffentlicht 05.12.2017 16:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The RSS Feed macro in Atlassian Confluence before version 6.5.2 allows remote attackers to inject arbitrary HTML or JavaScript via cross site scripting (XSS) vulnerabilities in various rss properties which were used as links without restriction on th...

Exploit
  • EPSS 0.39%
  • Veröffentlicht 15.06.2017 16:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Atlassian Confluence starting with 4.3.0 before 6.2.1 did not check if a user had permission to view a page when creating a workbox notification about new comments. An attacker who can login to Confluence could receive workbox notifications, which co...

  • EPSS 0.19%
  • Veröffentlicht 10.04.2017 03:59:01
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Atlassian Confluence Server before 5.9.11 has XSS on the viewmyprofile.action page.

  • EPSS 2.98%
  • Veröffentlicht 18.01.2017 22:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.10.6 allows remote attackers to inject arbitrary web script or HTML via the newFileName parameter to pages/doeditattachment.action.

  • EPSS 91.78%
  • Veröffentlicht 11.04.2016 21:59:11
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Atlassian Confluence before 5.8.17 allows remote authenticated users to read configuration files via the decoratorName parameter to (1) spaces/viewdefaultdecorator.action or (2) admin/viewdefaultdecorator.action.

  • EPSS 0.52%
  • Veröffentlicht 11.04.2016 21:59:10
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.8.17 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to rest/prototype/1/session/check.

  • EPSS 56.38%
  • Veröffentlicht 22.05.2012 15:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible before 2.5.8, 2.6 before 2.6.8, and 2.7 before 2.7.12; Bamboo before 3.3.4 and 3.4.x before 3.4.5; and Crowd before 2.0.9, 2.1 before...

  • EPSS 0.39%
  • Veröffentlicht 03.12.2005 19:03:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Cross-site scripting (XSS) vulnerability in the dosearchsite.action module in Atlassian Confluence 2.0.1 Build 321 allows remote attackers to inject arbitrary web script or HTML via the searchQuery.queryString search module parameter.