VYPR
Medium severity6.5NVD Advisory· Published Aug 15, 2018· Updated Jun 17, 2026

CVE-2018-13393

CVE-2018-13393

Description

The convertCommentToAnswer resource in Atlassian Confluence Questions before version 2.6.6, the bundled version of Confluence Questions was updated to a fixed version in Confluence version 6.9.0, allows remote attackers to modify a comment into an answer via a Cross-site request forgery (CSRF) vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:atlassian:questions_for_confluence:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:atlassian:questions_for_confluence:*:*:*:*:*:*:*:*range: <2.6.6
    • (no CPE)range: <2.6.6
    • (no CPE)range: unspecified

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.