EIP-2026-102358
PRE-CVEAppFusions Doxygen for Atlassian Confluence 1.3.2 - Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-102358. PoCs published by Julien Ahrens.
AI-analyzed exploit summary The advisory details a persistent XSS vulnerability in AppFusions Doxygen for Atlassian Confluence, where improper file validation allows arbitrary script code to be embedded in uploaded Doxygen files. The vulnerability is traced to the `renderContent()` method in `DoxygenFileServlet.java`, which fails to sanitize user input.
Description
AppFusions Doxygen for Atlassian Confluence 1.3.2 - Cross-Site Scripting
Exploits (1)
The advisory details a persistent XSS vulnerability in AppFusions Doxygen for Atlassian Confluence, where improper file validation allows arbitrary script code to be embedded in uploaded Doxygen files. The vulnerability is traced to the `renderContent()` method in `DoxygenFileServlet.java`, which fails to sanitize user input.