CVE-2018-13394

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
15/08/2018
Last modified:
12/10/2018

Description

The acceptAnswer resource in Atlassian Confluence Questions before version 2.6.6, the bundled version of Confluence Questions was updated to a fixed version in Confluence version 6.9.0, allows remote attackers to modify a comment into an answer via a Cross-site request forgery (CSRF) vulnerability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:atlassian:questions_for_confluence:*:*:*:*:*:*:*:* 2.6.6 (excluding)