CVE-2022-44724

The Handy Tip macro in Stiltsoft Handy Macros for Confluence Server/Data Center 3.x before 3.5.5 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:stiltsoft:handy_macros_for_confluence:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:28

Type Values Removed Values Added
References () https://stiltsoft.atlassian.net/browse/VD-3 - Patch, Vendor Advisory () https://stiltsoft.atlassian.net/browse/VD-3 - Patch, Vendor Advisory
References () https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2022-049.txt - Exploit, Third Party Advisory () https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2022-049.txt - Exploit, Third Party Advisory
CVSS v2 : unknown
v3 : 5.4
v2 : unknown
v3 : 8.9

Information

Published : 2022-11-04 07:15

Updated : 2024-11-21 07:28


NVD link : CVE-2022-44724

Mitre link : CVE-2022-44724

CVE.ORG link : CVE-2022-44724


JSON object : View

Products Affected

stiltsoft

  • handy_macros_for_confluence
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')