CVE-2015-8398
MEDIUMConfluence < 5.8.16 - Cross-Site Scripting via PATH_INFO to rest/prototype/1/session/check
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2015-8398. PoCs published by Sebastian Perez.
AI-analyzed exploit summary The document describes two vulnerabilities in Atlassian Confluence: a reflected XSS (CVE-2015-8398) and an Insecure Direct Object Reference (CVE-2015-8399). It includes PoC URLs for both vulnerabilities but does not contain executable exploit code.
Description
Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.8.17 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to rest/prototype/1/session/check.
Exploits (1)
The document describes two vulnerabilities in Atlassian Confluence: a reflected XSS (CVE-2015-8398) and an Insecure Direct Object Reference (CVE-2015-8399). It includes PoC URLs for both vulnerabilities but does not contain executable exploit code.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N