CVE-2019-20102: XSS
The attachment-uploading feature in Atlassian Confluence Server from version 6.14.0 through version 6.14.3, and version 6.15.0 before version 6.15.5 allows remote attackers to achieve stored cross-site- scripting (SXSS) via a malicious attachment with a modified mimeType parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-20102?
CVE-2019-20102 is a vulnerability in Atlassian Confluence Server that allows for stored cross-site scripting (SXSS) attacks via a malicious attachment.
How does CVE-2019-20102 affect Atlassian Confluence Server?
CVE-2019-20102 affects Atlassian Confluence Server versions 6.14.0 through 6.14.3, and versions 6.15.0 before 6.15.5.
What is the severity of CVE-2019-20102?
CVE-2019-20102 has a severity rating of medium with a CVSS score of 6.1.
How can remote attackers exploit CVE-2019-20102?
Remote attackers can exploit CVE-2019-20102 by uploading a malicious attachment with a modified 'mimeType' parameter.
Is there a fix for CVE-2019-20102?
Yes, the fix for CVE-2019-20102 is to upgrade to Atlassian Confluence Server version 6.14.4 or version 6.15.5.