CVE-2020-36290

CVE-2020-36290

The Livesearch macro in Confluence Server and Data Center before version 7.4.5, from version 7.5.0 before 7.6.3, and from version 7.7.0 before version 7.7.4 allows remote attackers with permission to edit a page or blog to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the page excerpt functionality.

Source: CVE-2020-36290

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다