CVE-2018-5227
published 2018-04-10CVE-2018-5227: Various administrative application link resources in Atlassian Application Links before version 5.4.4 allow remote attackers with administration rights to…
medium4.8CVSS 3.0
AVNACLPRHUIRSCCLILAN
Various administrative application link resources in Atlassian Application Links before version 5.4.4 allow remote attackers with administration rights to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the display url of a configured application link.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| atlassian | application_links | < 5.4.4 | 5.4.4 |
| atlassian | atlassian_application_links | >= unspecified < 5.4.4 | 5.4.4 |