CVE-2023-33287

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published May 31, 2023
Updated: Jan 10, 2025
CWE ID 79

Summary

CVE-2023-33287 is a stored cross-site scripting (XSS) vulnerability affecting the Inline Table Editing application of Confluence before version 3.8.0. This issue enables attackers to inject and execute arbitrary JavaScript codes by crafting malicious table data. Successful exploitation of this vulnerability can lead to unintended execution of malicious scripts on targeted user's browser, potentially resulting in unauthorized data access or theft. Users are strongly advised to update their Confluence installation to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share