Record summary

CVE-2021-26078 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit.

Description

The number range searcher component in Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before version 8.13.6, and from version 8.14.0 before version 8.16.1 allows remote attackers inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 17, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE ListBefore 8.5.14affected
8.6.0affected
Before 8.13.6affected
8.14.0affected
Before 8.16.1affected
CVE ListBefore 8.5.14affected
8.6.0affected
Before 8.13.6affected
8.14.0affected
Before 8.16.1affected

Proofs of concept

1

Catalogued exploits

ExploitDBAtlassian Jira Server Data Center 8.16.0 - Reflected Cross-Site Scripting (XSS)ExploitDB exploitby Captain_hookNot analyzed1 file
ExploitDB

PoC details

References

3