First published: Tue Jul 26 2022(Updated: )
The Livesearch macro in Confluence Server and Data Center before version 7.4.5, from version 7.5.0 before 7.6.3, and from version 7.7.0 before version 7.7.4 allows remote attackers with permission to edit a page or blog to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the page excerpt functionality.
Credit: security@atlassian.com
Affected Software | Affected Version | How to fix |
---|---|---|
Atlassian Confluence Data Center | <7.4.5 | |
Atlassian Confluence Data Center | >=7.5.0<7.6.3 | |
Atlassian Confluence Data Center | >=7.7.0<7.7.4 | |
Atlassian Confluence Server | <7.4.5 | |
Atlassian Confluence Server | >=7.5.0<7.6.3 | |
Atlassian Confluence Server | >=7.7.0<7.7.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-36290 is a vulnerability in Confluence Server and Data Center that allows remote attackers with permission to edit a page or blog to inject arbitrary HTML or JavaScript via a cross-site scripting (XSS) vulnerability.
CVE-2020-36290 has a severity rating of 5.4 (Medium).
CVE-2020-36290 affects Confluence Server and Data Center versions before 7.4.5, versions from 7.5.0 before 7.6.3, and versions from 7.7.0 before 7.7.4.
An attacker with permission to edit a page or blog can exploit CVE-2020-36290 by injecting arbitrary HTML or JavaScript via a cross-site scripting (XSS) vulnerability.
Yes, upgrading to Confluence Server and Data Center version 7.4.5 or later, version 7.6.3 or later, or version 7.7.4 or later will fix CVE-2020-36290.