Affected versions of Atlassian Confluence Server and Data Center allow remote malicious users to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in user macro parameters. The affected versions are before version 7.4.2, and from version 7.5.0 prior to 7.5.2.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
atlassian confluence server |
||
atlassian confluence data center |