EIP-2026-118707
PRE-CVEJira Scriptrunner 2.0.7 - Cross-Site Request Forgery / Remote Code Execution (Metasploit)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-118707. PoCs published by Ben Sheppard.
AI-analyzed exploit summary This Metasploit module exploits a CSRF vulnerability in Jira Scriptrunner 2.0.7 to achieve remote code execution (RCE) by submitting a crafted Groovy script via a hidden HTML form. The exploit generates a base64-encoded payload, writes it to an executable file, and executes it on the target system.
Description
Jira Scriptrunner 2.0.7 - Cross-Site Request Forgery / Remote Code Execution (Metasploit)
Exploits (1)
This Metasploit module exploits a CSRF vulnerability in Jira Scriptrunner 2.0.7 to achieve remote code execution (RCE) by submitting a crafted Groovy script via a hidden HTML form. The exploit generates a base64-encoded payload, writes it to an executable file, and executes it on the target system.