Atlassian Confluence Multiple Vulnerabilities Fixed by 5.8.17
Description
(#Multiple vulnerabilities have been identified in Confluence:#- CVE-2015-8398: cross-site scripting in the Rest API. A remote attacker could exploit it to execute arbitrary HTML/JavaScript code by enticing their victim into following a specially crafted link#- CVE-2015-8399: information disclosure. A remote attacker could exploit it to read the configuration files of the application by sending specially crafted web requests.##Proofs of concept are available for these vulnerabilities.)