Record summary

CVE-2020-14166 has a selected CVSS score of 4.8 (medium); EIP currently links 1 catalogued exploit.

Description

The /servicedesk/customer/portals resource in Jira Service Desk Server and Data Center before version 4.10.0 allows remote attackers with project administrator privileges to inject arbitrary HTML or JavaScript names via an Cross Site Scripting (XSS) vulnerability by uploading a html file.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Jira Service Desk Server and Data Center

Browse Atlassian / Jira Service Desk Server and Data Center
CVE ListBefore 4.10.0affected

Proofs of concept

1

Catalogued exploits

ExploitDBAtlassian Jira Service Desk 4.9.1 - Unrestricted File Upload to XSSExploitDB exploitby Captain_hookNot analyzed1 file
ExploitDB

PoC details

References

3