Description
The viewdefaultdecorator resource in Atlassian Confluence Server before version 6.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the key parameter.
Remediation
References
Related Vulnerabilities
SharePoint CVE-2022-41122 Vulnerability (CVE-2022-41122)
PHP Other Vulnerability (CVE-2007-1484)
MediaWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2024-40601)
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-3436)
Moodle Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2012-6103)