Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

The cross-site scripting (XSS) vulnerability affected blog post content shown on space homes using the news module with the content feed list mode. If the attacker is allowed to create/edit blog posts that are then added to the dashboard news module rotation, a potential script could be triggered. XSS vulnerabilities potentially allow an attacker to embed their own JavaScript into a Confluence blog post. 

You can read Read more about XSS attacks at http://www.cgisecurity.com/articles/xss-faq.shtml

If you have any questions regarding this matter please contact us at support@refined.com.

...