Cross-Site Scripting Vulnerability in Jira Service Desk Server and Data Center
CVE-2020-14166
4.8MEDIUM
Key Information:
- Vendor
- Atlassian
- Vendor
- CVE Published:
- 1 July 2020
Summary
A vulnerability in Jira Service Desk Server and Data Center prior to version 4.10.0 allows remote attackers with project administrator privileges to exploit a cross-site scripting (XSS) flaw. This occurs when an attacker uploads a malicious HTML file, enabling them to inject arbitrary HTML or JavaScript within the customer portal. The result can lead to serious implications for impacted users, including the potential for data theft or session hijacking.
Affected Version(s)
Jira Service Desk Server and Data Center < 4.10.0
References
CVSS V3.1
Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved