Cross-site Request Forgery Vulnerability in Atlassian Confluence Questions
CVE-2018-13393
6.5MEDIUM
What is CVE-2018-13393?
In Atlassian Confluence Questions prior to version 2.6.6, a Cross-site Request Forgery vulnerability is present in the convertCommentToAnswer resource. This flaw allows remote attackers to manipulate comments, converting them into answers without proper authorization, potentially leading to unauthorized content modifications.
Affected Version(s)
Confluence Questions < 2.6.6