CVE-2020-36290: XSS
The Livesearch macro in Confluence Server and Data Center before version 7.4.5, from version 7.5.0 before 7.6.3, and from version 7.7.0 before version 7.7.4 allows remote attackers with permission to edit a page or blog to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the page excerpt functionality.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-36290?
CVE-2020-36290 is a vulnerability in Confluence Server and Data Center that allows remote attackers with permission to edit a page or blog to inject arbitrary HTML or JavaScript via a cross-site scripting (XSS) vulnerability.
What is the severity of CVE-2020-36290?
CVE-2020-36290 has a severity rating of 5.4 (Medium).
Which versions of Confluence Server and Data Center are affected by CVE-2020-36290?
CVE-2020-36290 affects Confluence Server and Data Center versions before 7.4.5, versions from 7.5.0 before 7.6.3, and versions from 7.7.0 before 7.7.4.
How can an attacker exploit CVE-2020-36290?
An attacker with permission to edit a page or blog can exploit CVE-2020-36290 by injecting arbitrary HTML or JavaScript via a cross-site scripting (XSS) vulnerability.
Is there a fix for CVE-2020-36290?
Yes, upgrading to Confluence Server and Data Center version 7.4.5 or later, version 7.6.3 or later, or version 7.7.4 or later will fix CVE-2020-36290.