Loading
The acceptAnswer resource in Atlassian Confluence Questions before version 2.6.6, the bundled version of Confluence Questions was updated to a fixed version in Confluence version 6.9.0, allows remote attackers to modify a comment into an answer via a Cross-site request forgery (CSRF) vulnerability.
Use CWE-352, Atlassian vendor hub and Questions For Confluence product page to widen CVE-2018-13394 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2022-26138 and CVE-2018-13393 for nearby disclosures in the same product family.