First published: Thu Apr 22 2021(Updated: )
Affected versions of Team Calendar in Confluence Server before 7.11.0 allow attackers to inject arbitrary HTML or Javascript via a Cross Site Scripting Vulnerability in admin global setting parameters.
Credit: security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian Confluence Data Center | <7.11.0 | |
Atlassian Confluence Server | <7.11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2020-29444.
The title of this vulnerability is 'Affected versions of Team Calendar in Confluence Server before 7.11.0 allow attackers to inject arbitrary HTML or Javascript via a Cross Site Scripting Vulnerability in admin global setting parameters.'
The severity of CVE-2020-29444 is medium with a severity value of 5.4.
Affected versions of Team Calendar in Confluence Server before 7.11.0 are affected by CVE-2020-29444.
Attackers can exploit CVE-2020-29444 by injecting arbitrary HTML or Javascript via a Cross Site Scripting Vulnerability in admin global setting parameters.