First published: Wed Aug 14 2019(Updated: )
The "HTML Include and replace macro" plugin before 1.5.0 for Confluence Server allows a bypass of the includeScripts=false XSS protection mechanism via vectors involving an IFRAME element.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian Html Include And Replace Macro | >=1.1<=1.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-15053 is classified as a high severity vulnerability due to its potential for Cross-Site Scripting (XSS) attacks.
To fix CVE-2019-15053, upgrade the HTML Include and Replace Macro plugin to version 1.5.0 or later.
CVE-2019-15053 affects Confluence Server installations using versions prior to 1.5.0 of the HTML Include and Replace Macro plugin.
CVE-2019-15053 can facilitate Cross-Site Scripting (XSS) attacks by bypassing the XSS protection mechanism in the affected plugin.
The vendor for CVE-2019-15053 is Atlassian, which develops the HTML Include and Replace Macro plugin.