CVE-2020-24897

EUVD-2020-17605
The Table Filter and Charts for Confluence Server app before 5.3.25 (for Atlassian Confluence) allow remote attackers to inject arbitrary HTML or JavaScript via cross site scripting (XSS) through the provided Markdown markup to the "Table from CSV" macro.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.9 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L
mitreCNA
8.9 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AC:L/AV:N/A:L/C:H/I:H/PR:L/S:C/UI:R