Confluence - CVE-2023-22527

A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve remote code execution on an affected instance.

Affected Versions:

  • 8.0.x

  • 8.2.x

  • 8.3.x

  • 8.4.x

  • 8.5.0-8.5.3

POC

Simple one-liner usable with Burp. RCE response is seen in header X-Cmd-Response.

Python script to simplify the process:

Last updated

Was this helpful?