PT-2022-27285 · Stiltsoft · Stiltsoft Handy Macros For Confluence Server/Data Center

Patrick Schlüter

·

Published

2022-11-04

·

Updated

2023-02-03

·

CVE-2022-44724

CVSS v3.1

8.9

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Stiltsoft Handy Macros for Confluence Server/Data Center versions 3.x through 3.5.4
Description The issue allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the Handy Tip macro. This can be exploited by attackers to inject malicious code.
Recommendations For versions 3.x through 3.5.4, update to version 3.5.5 or later to resolve the issue. As a temporary workaround, consider disabling the Handy Tip macro until a patch is available. Restrict access to the macro to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-44724

Affected Products

Stiltsoft Handy Macros For Confluence Server/Data Center