Uploaded image for project: 'FishEye'
  1. FishEye
  2. FE-7163

Stored XSS in administrative linker functionality through the href parameter - CVE-2018-20240

      The administrative linker functionality in Atlassian Fisheye before version 4.7.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the href parameter.

            [FE-7163] Stored XSS in administrative linker functionality through the href parameter - CVE-2018-20240

            Marek Parfianowicz made changes -
            Component/s New: Repositories [ 15590 ]
            Component/s Original: linkers [ 46099 ]
            Themis made changes -
            Link New: This issue causes FE-7175 [ FE-7175 ]
            Marek Parfianowicz made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 418422 ]
            David Black made changes -
            Description Original: The administrative linker functionality in Atlassian Fisheye Crucible Development before version 4.7.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the href parameter. New: The administrative linker functionality in Atlassian Fisheye before version 4.7.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the href parameter.
            David Black made changes -
            Labels Original: CVE-2018-20240 cvss-medium security xss New: CVE-2018-20240 advisory advisory-released cvss-medium security xss
            David Black made changes -
            Link New: This issue relates to CRUC-8381 [ CRUC-8381 ]
            David Black made changes -
            Link New: This issue is detailed by FECRU-7678 [ FECRU-7678 ]
            Erin Jensby made changes -
            Security Original: Atlassian Staff [ 10750 ]
            Erin Jensby made changes -
            Labels Original: cvss-medium security xss New: CVE-2018-20240 cvss-medium security xss
            Erin Jensby made changes -
            Summary Original: Stored XSS in administrative linker functionality through the href parameter - CVE-2018-TBD New: Stored XSS in administrative linker functionality through the href parameter - CVE-2018-20240

              Unassigned Unassigned
              ejensby Erin Jensby
              Affected customers:
              0 This affects my team
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: