Cross-Site Scripting Vulnerability in Atlassian Confluence Server
CVE-2016-4317
5.4MEDIUM
Key Information:
- Vendor
Atlassian
- Vendor
- CVE Published:
- 10 April 2017
What is CVE-2016-4317?
Atlassian Confluence Server versions prior to 5.9.11 are prone to a Cross-Site Scripting (XSS) vulnerability on the viewmyprofile.action page. Malicious actors can exploit this flaw to inject arbitrary web scripts or HTML into user profiles, potentially leading to unauthorized actions and data exposure. Affected users are encouraged to update to the latest version to mitigate risks associated with this vulnerability.
Affected Version(s)
Atlassian Confluence Server before 5.9.11 Atlassian Confluence Server before 5.9.11