Cross-Site Scripting Vulnerability in Atlassian Fisheye and Crucible
CVE-2018-20241
5.4MEDIUM
What is CVE-2018-20241?
The Edit upload resource for a review in Atlassian Fisheye and Crucible prior to version 4.7.0 is susceptible to a cross-site scripting vulnerability. This issue arises when an attacker is able to inject arbitrary HTML or JavaScript through manipulation of the wbuser parameter, potentially compromising the integrity of the application and the security of the users interacting with it.
Affected Version(s)
Fisheye and Crucible < 4.7.0