EIP-2026-102488
PRE-CVEJira 4.0.1 - Cross-Site Scripting / Information Disclosure
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-102488. PoCs published by MaXe.
AI-analyzed exploit summary The exploit demonstrates XSS vulnerabilities in Jira by crafting malicious URLs with unsanitized input in the 'returnUrl' parameter. It leverages the application's failure to properly sanitize user-supplied data, allowing arbitrary script execution in the context of the victim's browser.
Description
Jira 4.0.1 - Cross-Site Scripting / Information Disclosure
Exploits (1)
The exploit demonstrates XSS vulnerabilities in Jira by crafting malicious URLs with unsanitized input in the 'returnUrl' parameter. It leverages the application's failure to properly sanitize user-supplied data, allowing arbitrary script execution in the context of the victim's browser.