CVE-2017-18084: XSS
The usermacros resource in Atlassian Confluence Server before version 6.3.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the description of a macro.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-18084?
The severity of CVE-2017-18084 is medium with a severity value of 4.8.
How does CVE-2017-18084 affect Atlassian Confluence?
CVE-2017-18084 affects Atlassian Confluence Server versions up to and including 6.3.4.
What can an attacker do with CVE-2017-18084?
An attacker can inject arbitrary HTML or JavaScript through a cross-site scripting (XSS) vulnerability in the description of a macro.
How can I fix CVE-2017-18084?
Update Atlassian Confluence Server to version 6.3.4 or later to fix CVE-2017-18084.
Where can I find more information about CVE-2017-18084?
More information about CVE-2017-18084 can be found at the following references: [SecurityFocus](http://www.securityfocus.com/bid/103064), [Atlassian JIRA](https://jira.atlassian.com/browse/CONFSERVER-54904).