PoC Index

CVE-2019-11581

KEVCRITICAL 9.8EPSS 84.6%

There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An attacker is able to remotely execute code on systems that run a vulnerable version of Jira Server or Data Center. All versions of Jira Server and Data Center from 4.4.0 before 7.6.14, from 7.7.0 before 7.13.5, from 8.0.0 before 8.0.3, from 8.1.0 before 8.1.2, and from 8.2.0 before 8.2.3 are affected by this vulnerability.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS
84.62% chance of exploitation in the next 30 days, 100th percentile
CISA KEV
added 2022-03-07
Nuclei
critical · CWE-74
Published
2019-08-09
Updated
2025-10-21

Proof-of-concept exploits (3)

Nuclei templates (1)

Vulhub environments (1)

Exploit collections (2)

References

Related