The MoroSystems EasyMind - Mind Maps plugin before 2.15.0 for Confluence allows persistent XSS when saving a Mind Map with the hyperlink parameter.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://marketplace.atlassian.com/apps/1211267/easymind-mind-maps-for-confluence/version-history | release notes |
https://y-security.de/news-en/easymind-cross-site-scripting-cve-2023-30452/index.html | third party advisory |