CVE-2020-14164
MEDIUMJira < 8.8.2 - Cross-Site Scripting via WYSIWYG Editor
Title source: llmDescription
The WYSIWYG editor resource in Jira Server and Data Center before version 8.8.2 allows remote attackers to inject arbitrary HTML or JavaScript names via an Cross Site Scripting (XSS) vulnerability by pasting javascript code into the editor field.
References (1)
Core 1
Core References
Issue Tracking, Vendor Advisory x_refsource_misc
https://jira.atlassian.com/browse/JRASERVER-71184
Scores
CVSS v3
6.1
EPSS
0.0030
EPSS Percentile
53.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (2)
atlassian/jira
< 8.8.2
atlassian/jira_software_data_center
< 8.8.2
Published
Jul 01, 2020
Tracked Since
Feb 18, 2026