CVE Published: 25/05/2023 |
CVE Updated: 01/10/2024 |
CVE Year: 2023 Source: atlassian |
Vendor: Atlassian |
Product: Confluence Data Center Status : PUBLISHED
CVE-2023-22504 Description
Affected versions of Atlassian Confluence Server allow remote attackers who have read permissions to a page, but not write permissions, to upload attachments via a Broken Access Control vulnerability in the attachments feature.