Cross-site Request Forgery Vulnerability in Atlassian Confluence Questions
CVE-2018-13394

6.5MEDIUM

Key Information:

Vendor
Atlassian
Vendor
CVE Published:
15 August 2018

Summary

A Cross-site Request Forgery vulnerability exists in Atlassian Confluence Questions prior to version 2.6.6, permitting remote attackers to alter comments and transform them into answers. By exploiting this flaw, attackers can unintentionally interact with the user's session, enabling unauthorized actions. This vulnerability was addressed in Confluence version 6.9.0 through the inclusion of security enhancements to mitigate the risk of such attacks.

Affected Version(s)

Confluence Questions < 2.6.6

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.