cbcvebase.
CVE-2018-13392
published 2018-08-13

CVE-2018-13392: Several resources in Atlassian Fisheye and Crucible before version 4.6.0 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site…

medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
Several resources in Atlassian Fisheye and Crucible before version 4.6.0 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in linked issue keys.

Affected

3 ranges
VendorProductVersion rangeFixed in
atlassiancrucible< 4.6.04.6.0
atlassianfisheye< 4.6.04.6.0
atlassianfisheye_and_crucible>= unspecified < 4.6.04.6.0