CVE-2019-15053
14.08.2019, 17:15
The "HTML Include and replace macro" plugin before 1.5.0 for Confluence Server allows a bypass of the includeScripts=false XSS protection mechanism via vectors involving an IFRAME element.
Vendor | Product | Version |
---|---|---|
atlassian | html_include_and_replace_macro | 1.1 ≤ 𝑥 ≤ 1.4.2 |
𝑥
= Vulnerable software versions