Description
The attachment-uploading feature in Atlassian Confluence Server from version 6.14.0 through version 6.14.3, and version 6.15.0 before version 6.15.5 allows remote attackers to achieve stored cross-site- scripting (SXSS) via a malicious attachment with a modified `mimeType` parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin Erident Custom Login and Dashboard Cross-Site Request Forgery (3.4.1)
WordPress Plugin Smash Balloon Social Post Feed Cross-Site Scripting (2.19.1)
Drupal Core Cross-Site Scripting (8.0.0 - 9.2.21)
Jenkins Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-2603)