CVE-2012-1500

MEDIUM

Atlassian Greenhopper < 5.9.8 - XSS

Title source: rule
STIX 2.1

Description

Stored XSS vulnerability in UpdateFieldJson.jspa in JIRA 4.4.3 and GreenHopper before 5.9.8 allows an attacker to inject arbitrary script code.

Exploits (1)

exploitdb WORKING POC
by Hoyt LLC Research · textwebappsjsp
https://www.exploit-db.com/exploits/21052

References (2)

Core 2
Core References
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/21052

Scores

CVSS v3 5.4
EPSS 0.0022
EPSS Percentile 44.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
atlassian/greenhopper < 5.9.8
atlassian/jira 4.4.3
Published Feb 13, 2020
Tracked Since Feb 18, 2026