CVE-2008-6831Cross-site Scripting in Atlassian Jira

Severity
4.3MEDIUMNVD
EPSS
0.5%
top 34.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 8
Latest updateMay 17

Description

Multiple cross-site scripting (XSS) vulnerabilities in Atlassian JIRA Enterprise Edition 3.13 allow remote attackers to inject arbitrary web script or HTML via the (1) fullname (Full Name) parameter in the ViewProfile page or (2) returnUrl parameter in a form, as demonstrated using secure/AddComment!default.jspa (aka "Add Comment").

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

NVDatlassian/jira3.13

Patches

🔴Vulnerability Details

2
GHSA
GHSA-c5g8-ww6r-9vf8: Multiple cross-site scripting (XSS) vulnerabilities in Atlassian JIRA Enterprise Edition 32022-05-17
CVEList
CVE-2008-6831: Multiple cross-site scripting (XSS) vulnerabilities in Atlassian JIRA Enterprise Edition 32009-06-08
CVE-2008-6831 — Cross-site Scripting in Atlassian Jira | cvebase