CVE-2020-24897
Summary
| CVE | CVE-2020-24897 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-08-29 20:15:00 UTC |
| Updated | 2020-09-04 16:53:00 UTC |
| Description | The Table Filter and Charts for Confluence Server app before 5.3.25 (for Atlassian Confluence) allow remote attackers to inject arbitrary HTML or JavaScript via cross site scripting (XSS) through the provided Markdown markup to the "Table from CSV" macro. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Stiltsoft | Table Filter And Charts For Confluence Server | All | All | All | All |
| Application | Stiltsoft | Table Filter And Charts For Confluence Server | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [VD-2] Cross-site scripting (XSS) in Table from CSV macro (Table Filter and Charts for Confluence Server) - CVE-2020-24897 - JIRA | MISC | stiltsoft.atlassian.net | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.