CVE-2023-26256
HIGH 7.5EPSS 11.6%
An unauthenticated path traversal vulnerability affects the "STAGIL Navigation for Jira - Menu & Themes" plugin before 2.0.52 for Jira. By modifying the fileName parameter to the snjFooterNavigationConfig endpoint, it is possible to traverse and read the file system.
- CVSS v3.1
- 7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - CVSS v3.1
- 7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - EPSS
- 11.62% chance of exploitation in the next 30 days, 96th percentile
- Nuclei
- high · CWE-22
- Published
- 2023-02-28
- Updated
- 2025-03-21
Proof-of-concept exploits (7)
- 1nters3ct/CVEs/blob/main/CVE-2023-26256.md
- 0x7eTeam/CVE-2023-2625632★ · 2023-08-24
- aodsec/CVE-2023-2625632★ · 2023-08-24
- csdcsdcsdcsdcsd/CVE-2023-262560★ · 2023-08-29
- jcad123/CVE-2023-262563★ · 2023-09-01
- qs119/CVE-2023-262560★ · 2023-08-30
- xhs-d/CVE-2023-262560★ · 2023-08-29