ZeroHour

CVE-2021-26082

CVSS 3.1
5.4 medium
EPSS
<1%p61
Published
()
Modified
Description

The XML Export in Atlassian Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.17.0 allows remote attackers to inject arbitrary HTML or JavaScript via a stored cross site scripting vulnerability.

Vendors
atlassian
Products
data center, jira, jira data center, jira server
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.