CVE-2016-4317: XSS
Published Apr 10, 2017
·Updated
Atlassian Confluence Server before 5.9.11 has XSS on the viewmyprofile.action page.
Affected Software
1 affected component
Atlassian Confluence<=5.9.10
Event History
Apr 10, 2017
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-4317?
CVE-2016-4317 is classified as a medium severity Cross-Site Scripting (XSS) vulnerability.
2
How do I fix CVE-2016-4317?
To fix CVE-2016-4317, upgrade Atlassian Confluence to version 5.9.11 or later.
3
What versions of Atlassian Confluence are affected by CVE-2016-4317?
CVE-2016-4317 affects all versions of Atlassian Confluence prior to 5.9.11.
4
Can CVE-2016-4317 be exploited remotely?
Yes, CVE-2016-4317 can be exploited remotely through the viewmyprofile.action page.
5
What impact can CVE-2016-4317 have on users?
CVE-2016-4317 allows attackers to execute arbitrary scripts in the context of a user's session.