CVE-2014-8658

EUVD-2014-8494
Cross-site scripting (XSS) vulnerability in RefinedWiki Original Theme 3.x before 3.5.13 and 4.x before 4.0.12 for Confluence allows remote authenticated users with permissions to create or edit content to inject arbitrary web script or HTML via the versionComment parameter to pages/doeditpage.action.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:S/C:N/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 44%
Affected Products (NVD)
VendorProductVersion
refinedwikirefinedwiki_original_theme
3.5
refinedwikirefinedwiki_original_theme
3.5.1
refinedwikirefinedwiki_original_theme
3.5.2
refinedwikirefinedwiki_original_theme
3.5.3
refinedwikirefinedwiki_original_theme
3.5.4
refinedwikirefinedwiki_original_theme
3.5.5
refinedwikirefinedwiki_original_theme
3.5.6
refinedwikirefinedwiki_original_theme
3.5.7
refinedwikirefinedwiki_original_theme
3.5.8
refinedwikirefinedwiki_original_theme
3.5.9
refinedwikirefinedwiki_original_theme
3.5.10
refinedwikirefinedwiki_original_theme
3.5.11
refinedwikirefinedwiki_original_theme
3.5.12
refinedwikirefinedwiki_original_theme
3.5.13
refinedwikirefinedwiki_original_theme
4.0
refinedwikirefinedwiki_original_theme
4.0.1
refinedwikirefinedwiki_original_theme
4.0.2
refinedwikirefinedwiki_original_theme
4.0.3
refinedwikirefinedwiki_original_theme
4.0.4
refinedwikirefinedwiki_original_theme
4.0.5
refinedwikirefinedwiki_original_theme
4.0.6
refinedwikirefinedwiki_original_theme
4.0.7
refinedwikirefinedwiki_original_theme
4.0.8
refinedwikirefinedwiki_original_theme
4.0.9
refinedwikirefinedwiki_original_theme
4.0.10
refinedwikirefinedwiki_original_theme
4.0.11
𝑥
= Vulnerable software versions