CVE-2014-8658: XSS
Cross-site scripting (XSS) vulnerability in RefinedWiki Original Theme 3.x before 3.5.13 and 4.x before 4.0.12 for Confluence allows remote authenticated users with permissions to create or edit content to inject arbitrary web script or HTML via the versionComment parameter to pages/doeditpage.action.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8658?
The severity of CVE-2014-8658 is classified as high due to the potential for remote authenticated users to inject arbitrary web scripts or HTML.
How do I fix CVE-2014-8658?
To fix CVE-2014-8658, update the RefinedWiki Original Theme to version 4.0.12 or later.
What kind of vulnerability is CVE-2014-8658?
CVE-2014-8658 is a cross-site scripting (XSS) vulnerability.
Who is affected by CVE-2014-8658?
Users of RefinedWiki Original Theme versions 3.x before 3.5.13 and 4.x before 4.0.12 for Confluence are affected by CVE-2014-8658.
Can CVE-2014-8658 be exploited by unauthenticated users?
No, CVE-2014-8658 requires remote authenticated users with permissions to create or edit content to exploit the vulnerability.