CVE-2018-20824

CVE-2018-20824: vulnerability in Atlassian Jira

Published · Updated

30Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 38%
exploitation probability
38%top 1% of all CVEs
observed exploitation
nono source reports it
The WallboardServlet resource in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the cyclePeriod parameter.
Affected products
Atlassian · Jira