Security Advisory

CVE-2018-13393

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2018-08-15 12:00:00
Last updated 2024-09-16 18:23:29
Assigner atlassian
State PUBLISHED

Description

The convertCommentToAnswer resource in Atlassian Confluence Questions before version 2.6.6, the bundled version of Confluence Questions was updated to a fixed version in Confluence version 6.9.0, allows remote attackers to modify a comment into an answer via a Cross-site request forgery (CSRF) vulnerability.