The Handy Tip macro in Stiltsoft Handy Macros for Confluence Server/Data Center 3.x before 3.5.5 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability.
Metrics
CVSS Version: 3.1 |
Base Score: 8.9 HIGH Vector: CVSS:3.1/AC:L/AV:N/A:L/C:H/I:H/PR:L/S:C/UI:R