4.3
CVSSv2

CVE-2015-8398

Published: 11/04/2016 Updated: 09/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in Atlassian Confluence prior to 5.8.17 allows remote malicious users to inject arbitrary web script or HTML via the PATH_INFO to rest/prototype/1/session/check.

Vulnerable Product Search on Vulmon Subscribe to Product

atlassian confluence

Exploits

[Systems Affected] Product : Confluence Company : Atlassian Versions (1) : 52 / 5814 / 5815 CVSS Score (1) : 61 / Medium (classified by vendor) Versions (2) : 591 / 5814 / 5815 CVSS Score (2) : 77 / High (classified by vendor) [Product Description] ...
Atlassian Confluence suffers from cross site scripting and insecure direct object reference vulnerabilities The cross site scripting affects versions 52, 5814, and 5815 The reference vulnerability affects versions 591, 5814, and 5815 ...