XSS Vulnerability in Atlassian Fisheye and Crucible Affecting Versions Prior to 4.7.0
CVE-2018-20240
4.8MEDIUM
What is CVE-2018-20240?
The administrative linker feature in Atlassian Fisheye and Crucible prior to version 4.7.0 contains a cross-site scripting (XSS) vulnerability. This allows remote attackers to inject malicious HTML or JavaScript into the href parameter, leading to potential unauthorized actions or data exposure on affected installations. Users should apply available updates to mitigate this security risk.
Affected Version(s)
Fisheye and Crucible < 4.7.0