CVE-2020-14166
Summary
| CVE | CVE-2020-14166 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-07-01 02:15:00 UTC |
| Updated | 2022-02-01 17:41:00 UTC |
| Description | The /servicedesk/customer/portals resource in Jira Service Desk Server and Data Center before version 4.10.0 allows remote attackers with project administrator privileges to inject arbitrary HTML or JavaScript names via an Cross Site Scripting (XSS) vulnerability by uploading a html file. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [JSDSERVER-6895] XSS in API and Integrations - CVE-2020-14166 - Create and track feature requests for Atlassian products. |
MISC |
jira.atlassian.com |
Issue Tracking, Vendor Advisory |
| Atlassian Jira Service Desk 4.9.1 Cross Site Scripting ≈ Packet Storm |
MISC |
packetstormsecurity.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 730460 Atlassian Jira Service Desk Server and Data Center Cross-Site Scripting (XSS) Vulnerability (JSDSERVER-6895)