-
Bug
-
Resolution: Fixed
-
Low
-
4.6.1
-
Severity 3 - Minor
-
The administrative linker functionality in Atlassian Fisheye before version 4.7.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the href parameter.
[FE-7163] Stored XSS in administrative linker functionality through the href parameter - CVE-2018-20240
Component/s | New: Repositories [ 15590 ] | |
Component/s | Original: linkers [ 46099 ] |
Remote Link | New: This issue links to "Page (Confluence)" [ 418422 ] |
Description | Original: The administrative linker functionality in Atlassian Fisheye Crucible Development before version 4.7.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the href parameter. | New: The administrative linker functionality in Atlassian Fisheye before version 4.7.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the href parameter. |
Labels | Original: CVE-2018-20240 cvss-medium security xss | New: CVE-2018-20240 advisory advisory-released cvss-medium security xss |
Link | New: This issue is detailed by FECRU-7678 [ FECRU-7678 ] |
Security | Original: Atlassian Staff [ 10750 ] |
Labels | Original: cvss-medium security xss | New: CVE-2018-20240 cvss-medium security xss |
Summary | Original: Stored XSS in administrative linker functionality through the href parameter - CVE-2018-TBD | New: Stored XSS in administrative linker functionality through the href parameter - CVE-2018-20240 |