Security Advisory

CVE-2020-14175

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2020-07-24 07:05:16
Last updated 2024-09-16 20:58:53
Assigner atlassian
State PUBLISHED

Description

Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in user macro parameters. The affected versions are before version 7.4.2, and from version 7.5.0 before 7.5.2.