CVE-2018-13393: CSRF
Published Aug 15, 2018
·Updated
The convertCommentToAnswer resource in Atlassian Confluence Questions before version 2.6.6, the bundled version of Confluence Questions was updated to a fixed version in Confluence version 6.9.0, allows remote attackers to modify a comment into an answer via a Cross-site request forgery (CSRF) vulnerability.
Affected Software
1 affected component
Atlassian Questions For Confluence<2.6.6
Event History
Aug 15, 2018
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-13393.
2
What is the severity level of CVE-2018-13393?
CVE-2018-13393 has a severity level of medium (6.5).
3
How does CVE-2018-13393 affect Atlassian Confluence Questions?
CVE-2018-13393 affects Atlassian Confluence Questions before version 2.6.6.
4
What is the impact of CVE-2018-13393?
CVE-2018-13393 allows remote attackers to modify a comment into an answer via a Cross-site request forgery (CSRF) vulnerability.
5
Is there a fix available for CVE-2018-13393?
Yes, the bundled version of Confluence Questions was updated to a fixed version in Confluence version 6.9.0.