ZeroHour

CVE-2020-15943

PoC ×3
CVSS 3.1
8.1 high
EPSS
2%p81
Published
()
Modified
Description

An issue was discovered in the Gantt-Chart module before 5.5.4 for Jira. Due to a missing privilege check, it is possible to read and write to the module configuration of other users. This can also be used to deliver an XSS payload to other users' dashboards. To exploit this vulnerability, an attacker has to be authenticated.

Vendors
gantt-chart project
Products
gantt-chart
Weakness
CWE-79, CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.