CVE-2020-24898

HIGH

Confluence Server < 5.3.26 - SSRF via Table from CSV Macro URL Parameter

Title source: llm
STIX 2.1

Description

The Table Filter and Charts for Confluence Server app before 5.3.26 (for Atlassian Confluence) allows SSRF via the "Table from CSV" macro (URL parameter).

References (1)

Core 1
Core References
Third Party Advisory x_refsource_misc
https://stiltsoft.atlassian.net/browse/VD-1

Scores

CVSS v3 7.6
EPSS 0.0066
EPSS Percentile 47.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L

Details

CWE
CWE-918
Status published
Products (1)
stiltsoft/table_filter_and_charts_for_confluence_server < 5.3.26
Published Aug 29, 2020
Tracked Since Feb 18, 2026