CVE-2020-24897 is a high-severity cross-site scripting (XSS) vulnerability affecting the Table Filter and Charts for Confluence Server app prior to version 5.3.25. This flaw allows authenticated remote attackers to inject arbitrary HTML or JavaScript into Confluence pages through the "Table from CSV" macro by leveraging Markdown markup. With a CVSS score of 8.9 (HIGH), the vulnerability has a low attack complexity and requires user interaction, but can lead to high impact on confidentiality and integrity, and low impact on availability. The EPSS score is very low, indicating a minimal probability of exploitation in the wild. Currently, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. The vulnerability has garnered no community discussion or media coverage, suggesting a low level of public awareness or interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.3.25CPE matchmatch criteria | cpe:2.3:a:stiltsoft:table_filter_and_charts_for_confluence_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.