CVE-2017-18100 β€” Cross-site Scripting in Atlassian Jira

Severity
6.1MEDIUMNVD
EPSS
0.2%
top 61.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 10
Latest updateMay 14

Description

The agile wallboard gadget in Atlassian Jira before version 7.8.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of quick filters.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages1 packages

β–ΆNVDatlassian/jira< 7.8.1

πŸ”΄Vulnerability Details

2
GHSA
GHSA-w89h-rg2q-xpj2: The agile wallboard gadget in Atlassian Jira before version 7β†—2022-05-14
β–Ά
CVEList
CVE-2017-18100: The agile wallboard gadget in Atlassian Jira before version 7β†—2018-04-10
β–Ά
CVE-2017-18100 β€” Cross-site Scripting in Atlassian Jira | cvebase