XSS Vulnerability in Atlassian Fisheye and Crucible
CVE-2017-14587

5.4MEDIUM

Key Information:

Vendor
Atlassian
Vendor
CVE Published:
11 October 2017

Summary

The administration user deletion feature in Atlassian Fisheye and Crucible prior to version 4.4.2 is susceptible to a Cross-Site Scripting (XSS) vulnerability. Remote attackers can exploit this flaw by injecting arbitrary HTML or JavaScript through the 'uname' parameter. This can lead to unauthorized access to sensitive user data or further attacks on the application environment.

Affected Version(s)

Atlassian Fisheye and Crucible All versions prior to version 4.4.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.