CVE-2016-6283: XSS
Published Jan 18, 2017
·Updated
Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.10.6 allows remote attackers to inject arbitrary web script or HTML via the newFileName parameter to pages/doeditattachment.action.
Affected Software
1 affected component
Atlassian Confluence<=5.10.5
Event History
Jan 18, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Data Sourced
via NVD·10:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-6283?
CVE-2016-6283 has a medium severity rating due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2016-6283?
To fix CVE-2016-6283, upgrade to Atlassian Confluence version 5.10.6 or later.
3
What type of vulnerability is CVE-2016-6283?
CVE-2016-6283 is classified as a cross-site scripting (XSS) vulnerability.
4
Who is affected by CVE-2016-6283?
CVE-2016-6283 affects all versions of Atlassian Confluence prior to 5.10.6.
5
What can an attacker do with CVE-2016-6283?
An attacker can inject arbitrary web script or HTML into pages using the newFileName parameter.