vendor:
Jira Service Desk
by:
Captain_hook
4.8
CVSS
MEDIUM
Cross Site Scripting (XSS)
79
CWE
Product Name: Jira Service Desk
Affected Version From: < 4.10.0
Affected Version To: < 4.10.0
Patch Exists: YES
Related CWE: CVE-2020-14166
CPE: a:atlassian:jira_service_desk
Other Scripts:
N/A
Platforms Tested: All OS
2020
Atlassian Jira Service Desk 4.9.1 – Unrestricted File Upload to XSS
The /servicedesk/customer/portals resource in Jira Service Desk Server and Data Center before version 4.10.0 allows remote attackers with project administrator privileges to inject arbitrary HTML or JavaScript names via an Cross Site Scripting (XSS) vulnerability by uploading a html file.
Mitigation:
Upgrade to Jira Service Desk Server and Data Center version 4.10.0 or later.