Cross-Site Scripting Vulnerability in Jira Service Desk Server and Data Center
CVE-2020-14166

4.8MEDIUM

Key Information:

Vendor
Atlassian
Vendor
CVE Published:
1 July 2020

Summary

A vulnerability in Jira Service Desk Server and Data Center prior to version 4.10.0 allows remote attackers with project administrator privileges to exploit a cross-site scripting (XSS) flaw. This occurs when an attacker uploads a malicious HTML file, enabling them to inject arbitrary HTML or JavaScript within the customer portal. The result can lead to serious implications for impacted users, including the potential for data theft or session hijacking.

Affected Version(s)

Jira Service Desk Server and Data Center < 4.10.0

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.