3.5
CVSSv2

CVE-2020-14166

Published: 01/07/2020 Updated: 01/02/2022
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 4.8 | Impact Score: 2.7 | Exploitability Score: 1.7
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

The /servicedesk/customer/portals resource in Jira Service Desk Server and Data Center before version 4.10.0 allows remote attackers with project administrator privileges to inject arbitrary HTML or JavaScript names via an Cross Site Scripting (XSS) vulnerability by uploading a html file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

atlassian jira service desk

Exploits

Atlassian Jira Service Desk version 491 suffers from a cross site scripting vulnerability via a file upload ...