CVE-2023-33287
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published May 31, 2023
Updated: Jan 10, 2025
CWE ID 79
Summary
CVE-2023-33287 is a stored cross-site scripting (XSS) vulnerability affecting the Inline Table Editing application of Confluence before version 3.8.0. This issue enables attackers to inject and execute arbitrary JavaScript codes by crafting malicious table data. Successful exploitation of this vulnerability can lead to unintended execution of malicious scripts on targeted user's browser, potentially resulting in unauthorized data access or theft. Users are strongly advised to update their Confluence installation to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.