PoC Index

CVE-2018-5230

MEDIUM 6.1EPSS 37.6%

The issue collector in Atlassian Jira before version 7.6.6, from version 7.7.0 before version 7.7.4, from version 7.8.0 before version 7.8.4 and from version 7.9.0 before version 7.9.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the error message of custom fields when an invalid value is specified.

CVSS v3.0
6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
37.61% chance of exploitation in the next 30 days, 98th percentile
Nuclei
medium · CWE-79
Published
2018-05-14
Updated
2024-09-16

Nuclei templates (1)

References

Related