4
CVSSv2

CVE-2015-8399

Published: 11/04/2016 Updated: 09/10/2018
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 405
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

Atlassian Confluence prior to 5.8.17 allows remote authenticated users to read configuration files via the decoratorName parameter to (1) spaces/viewdefaultdecorator.action or (2) admin/viewdefaultdecorator.action.

Vulnerable Product Search on Vulmon Subscribe to Product

atlassian confluence

Exploits

[Systems Affected] Product : Confluence Company : Atlassian Versions (1) : 52 / 5814 / 5815 CVSS Score (1) : 61 / Medium (classified by vendor) Versions (2) : 591 / 5814 / 5815 CVSS Score (2) : 77 / High (classified by vendor) [Product Description] ...
Atlassian Confluence suffers from cross site scripting and insecure direct object reference vulnerabilities The cross site scripting affects versions 52, 5814, and 5815 The reference vulnerability affects versions 591, 5814, and 5815 ...