Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Aryaka IT November 2, 2021

Atlassian Confluence: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') (CVE-2021-37412)
The TechRadar app 1.1 for Confluence Server allows XSS via the Title field of a Radar.

We don't see any plugin installed, how to verify if its removed completely. 

1 answer

0 votes
Brant Schroeder
Community Champion
November 2, 2021

@Aryaka IT I would suggest using the KB to manually remove the app from the plugins folder if you are concerned that it could still be causing an issue.  https://confluence.atlassian.com/confkb/how-to-manually-remove-malfunctioning-add-ons-113705118.html

Aryaka IT November 3, 2021

We have verified the server plugin folders and confluence DB as per the above URL descriptions and could not find the "Tech Radar" app/plugin . Please advise how to troubleshoot further. 

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
SERVER
TAGS
AUG Leaders

Atlassian Community Events