CVE-2020-14164

MEDIUM

Jira < 8.8.2 - Cross-Site Scripting via WYSIWYG Editor

Title source: llm
STIX 2.1

Description

The WYSIWYG editor resource in Jira Server and Data Center before version 8.8.2 allows remote attackers to inject arbitrary HTML or JavaScript names via an Cross Site Scripting (XSS) vulnerability by pasting javascript code into the editor field.

References (1)

Core 1
Core References
Issue Tracking, Vendor Advisory x_refsource_misc
https://jira.atlassian.com/browse/JRASERVER-71184

Scores

CVSS v3 6.1
EPSS 0.0030
EPSS Percentile 53.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
atlassian/jira < 8.8.2
atlassian/jira_software_data_center < 8.8.2
Published Jul 01, 2020
Tracked Since Feb 18, 2026