CVE-2017-18083: XSS
The editinword resource in Atlassian Confluence Server before version 6.4.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the contents of an uploaded file.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-18083?
CVE-2017-18083 is a vulnerability in Atlassian Confluence Server that allows remote attackers to inject arbitrary HTML or JavaScript via a cross-site scripting (XSS) vulnerability.
How does CVE-2017-18083 affect Atlassian Confluence Server?
CVE-2017-18083 affects Atlassian Confluence Server versions before 6.4.0.
What is the severity of CVE-2017-18083?
CVE-2017-18083 has a severity rating of medium, with a score of 5.4.
How can remote attackers exploit CVE-2017-18083?
Remote attackers can exploit CVE-2017-18083 by uploading a file containing malicious HTML or JavaScript code.
Is there a fix available for CVE-2017-18083?
Yes, a fix is available for CVE-2017-18083 in Atlassian Confluence Server version 6.4.0 and later.