4.8
CVE-2020-14166
- EPSS 0.66%
- Veröffentlicht 01.07.2020 02:15:11
- Zuletzt bearbeitet 21.11.2024 05:02:47
- Quelle security@atlassian.com
- CVE-Watchlists
- Unerledigt
The /servicedesk/customer/portals resource in Jira Service Desk Server and Data Center before version 4.10.0 allows remote attackers with project administrator privileges to inject arbitrary HTML or JavaScript names via an Cross Site Scripting (XSS) vulnerability by uploading a html file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Atlassian ≫ Jira Service Desk SwEditiondata_center Version < 4.10.0
Atlassian ≫ Jira Service Desk SwEditionserver Version < 4.10.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.66% | 0.703 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.8 | 1.7 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
|
| nvd@nist.gov | 3.5 | 6.8 | 2.9 |
AV:N/AC:M/Au:S/C:N/I:P/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.