CVE-2020-14175: XSS
Published Jul 24, 2020
·Updated
Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in user macro parameters. The affected versions are before version 7.4.2, and from version 7.5.0 before 7.5.2.
Affected Software
4 affected components
Atlassian Confluence Data Center<7.4.2
Atlassian Confluence Data Center>=7.5.0<7.5.2
Atlassian Confluence Server<7.4.2
Atlassian Confluence Server>=7.5.0<7.5.2
Event History
Jul 24, 2020
CVE Published
via MITRE·07:05 AM
Data Sourced
via MITRE·07:05 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Confluence Server and Data Center vulnerability?
The vulnerability ID is CVE-2020-14175.
2
What is the severity level of CVE-2020-14175?
The severity level of CVE-2020-14175 is medium with a CVSS score of 5.4.
3
Which versions of Atlassian Confluence Server and Data Center are affected by CVE-2020-14175?
Versions before 7.4.2 and from 7.5.0 to 7.5.2 of Atlassian Confluence Server and Data Center are affected by CVE-2020-14175.
4
What is the type of vulnerability in CVE-2020-14175?
CVE-2020-14175 is a Cross-Site Scripting (XSS) vulnerability.
5
How can an attacker exploit CVE-2020-14175?
Remote attackers can exploit CVE-2020-14175 by injecting arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in user macro parameters.