packetstormsecurity.com
http://packetstormsecurity.com/files/162107/Atlassian-Jira-Service-Desk-4.9.1-Cross-Site-Scripting.html CVE-2020-14166
MEDIUM
Atlassian Jira Service Desk 4.9.1 - Unrestricted File Upload to XSS
Record summary
CVE-2020-14166 has a selected CVSS score of 4.8 (medium); EIP currently links 1 catalogued exploit.
Description
The /servicedesk/customer/portals resource in Jira Service Desk Server and Data Center before version 4.10.0 allows remote attackers with project administrator privileges to inject arbitrary HTML or JavaScript names via an Cross Site Scripting (XSS) vulnerability by uploading a html file.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Jira Service Desk Server and Data CenterBrowse Atlassian / Jira Service Desk Server and Data Center | CVE List | Before 4.10.0 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBAtlassian Jira Service Desk 4.9.1 - Unrestricted File Upload to XSSExploitDB exploitby Captain_hookNot analyzed1 file
References
3jira.atlassian.com
https://jira.atlassian.com/browse/JSDSERVER-6895 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-14166