Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Stefano Castilletti

Researcher fromApple
#26570of 53,633
9.7Total CVSS
Vulnerabilities · 2
Medium
2
PT-2021-11665
5.4
2021-05-07
Atlassian · Confluence · CVE-2020-29444
Name of the Vulnerable Software and Affected Versions: Confluence Server versions prior to 7.11.0 Description: The issue allows attackers to inject arbitrary HTML or Javascript via a Cross Site Scripting vulnerability in admin global setting parameters. Recommendations: For versions prior to 7.11.0, update to version 7.11.0 or later to resolve the issue.
PT-2021-11666
4.3
2021-05-07
Atlassian · Confluence · CVE-2020-29445
Name of the Vulnerable Software and Affected Versions: Confluence Server versions prior to 7.4.8 Confluence Server versions 7.5.0 through 7.10.9 Description: The issue allows attackers to identify internal hosts and ports via a blind server-side request forgery vulnerability in Team Calendars parameters. Recommendations: For Confluence Server versions prior to 7.4.8, update to version 7.4.8 or later. For Confluence Server versions 7.5.0 through 7.10.9, update to version 7.11.0 or later.