📦

questions_for_confluence

Vendor: atlassian

Actively Exploited 1 CISA KEV List
PoC / Exploits 1 Code Available
Total RCEs 0 Remote Access
Total CVEs 5 Total Indexed
Avg. EPSS 33.27% Exploit Prob.
Latest CVE CVE-2022-26138 Jul 20

Security Vulnerability Index

Page 1 / 1
Critical Target
9.8 CVSS
CVE-2022-26138
Exploit Found

The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group. This user account is created when installing versions 2.7.34, 2.7.35, and 3.0.2 of the app.

EPSS: 98.17%
6.5 CVSS

The acceptAnswer resource in Atlassian Confluence Questions before version 2.6.6, the bundled version of Confluence Questions was updated to a fixed version in Confluence version 6.9.0, allows remote attackers to modify a comment into an answer via a Cross-site request forgery (CSRF) vulnerability.

EPSS: 0.84%
6.5 CVSS

The convertCommentToAnswer resource in Atlassian Confluence Questions before version 2.6.6, the bundled version of Confluence Questions was updated to a fixed version in Confluence version 6.9.0, allows remote attackers to modify a comment into an answer via a Cross-site request forgery (CSRF) vulnerability.

EPSS: 0.80%