CVE-2014-8658
Cross-site scripting (XSS) vulnerability in RefinedWiki Original Theme 3.x before 3.5.13 and 4.x before 4.0.12 for Confluence allows remote authenticated users with permissions to create or edit content to inject arbitrary web script or HTML via the…
Does this matter?
Lower severity and a low EPSS score (1.84%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in RefinedWiki Original Theme 3.x before 3.5.13 and 4.x before 4.0.12 for Confluence allows remote authenticated users with permissions to create or edit content to inject arbitrary web script or HTML via the versionComment parameter to pages/doeditpage.action.
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
- EPSS
- 1.84% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- refinedwiki/refinedwiki original theme
- Source
- cve@mitre.org
References
- http://demo.refinedwiki.com/display/rwot/Version+4.0.12Vendor Advisory
- http://packetstormsecurity.com/files/128907/Confluence-RefinedWiki-Original-Theme-Cross-Site-Scripting.htmlExploit
- http://seclists.org/fulldisclosure/2014/Oct/126
- http://www.securityfocus.com/archive/1/533845/100/0/threaded
- http://www.securityfocus.com/bid/70798
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98401
- https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20141029-1_RefinedWiki-OriginalTheme_Persistent-Cross-Site-Scripting_v10.txtExploit
- http://demo.refinedwiki.com/display/rwot/Version+4.0.12Vendor Advisory
- http://packetstormsecurity.com/files/128907/Confluence-RefinedWiki-Original-Theme-Cross-Site-Scripting.htmlExploit
- http://seclists.org/fulldisclosure/2014/Oct/126
- http://www.securityfocus.com/archive/1/533845/100/0/threaded
- http://www.securityfocus.com/bid/70798
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98401
- https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20141029-1_RefinedWiki-OriginalTheme_Persistent-Cross-Site-Scripting_v10.txtExploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.