Cross-site Request Forgery Vulnerability in Atlassian Confluence Questions
CVE-2018-13394
6.5MEDIUM
What is CVE-2018-13394?
A Cross-site Request Forgery vulnerability exists in Atlassian Confluence Questions prior to version 2.6.6, permitting remote attackers to alter comments and transform them into answers. By exploiting this flaw, attackers can unintentionally interact with the user's session, enabling unauthorized actions. This vulnerability was addressed in Confluence version 6.9.0 through the inclusion of security enhancements to mitigate the risk of such attacks.
Affected Version(s)
Confluence Questions < 2.6.6