#VU83896 Template injection in Confluence Server and Confluence Data Center - CVE-2023-22522
Published: December 6, 2023 / Updated: March 22, 2024
Confluence Server
Confluence Data Center
Atlassian
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation. A remote attacker (both authenticated and with anonymous access) can inject an unsafe user input into a Confluence page and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.