01642 06 11 11 Arrange Call

Arbitrary HTML and JavaScript Injection via File Upload in Jira Service Desk Server and Data Center

CVE-2020-14166 · MEDIUM

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

CVE-2020-14166

The /servicedesk/customer/portals resource in Jira Service Desk Server and Data Center before version 4.10.0 allows remote attackers with project administrator privileges to inject arbitrary HTML or JavaScript names via an Cross Site Scripting (XSS) vulnerability by uploading a html file.

Learn more about our Cis Benchmark Audit For Server Software.