Cross-site Request Forgery Vulnerability in Atlassian Confluence Questions
CVE-2018-13394
6.5MEDIUM
Summary
A Cross-site Request Forgery vulnerability exists in Atlassian Confluence Questions prior to version 2.6.6, permitting remote attackers to alter comments and transform them into answers. By exploiting this flaw, attackers can unintentionally interact with the user's session, enabling unauthorized actions. This vulnerability was addressed in Confluence version 6.9.0 through the inclusion of security enhancements to mitigate the risk of such attacks.
Affected Version(s)
Confluence Questions < 2.6.6
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved