Description
The editinword resource in Atlassian Confluence Server before version 6.4.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the contents of an uploaded file.
Remediation
References
Related Vulnerabilities
WordPress Plugin Video Metabox Cross-Site Scripting (1.1)
Apache Tomcat Other Vulnerability (CVE-2007-3384)
MediaWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2014-5241)
Drupal Inclusion of Functionality from Untrusted Control Sphere Vulnerability (CVE-2017-6381)
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2007-3378)