← back
CVE-2018-20824

CVE-2018-20824

30Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 38%
exploitation probability
38%top 2% of all CVEs
observed exploitation
nono source reports it
The WallboardServlet resource in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the cyclePeriod parameter.
Affected products
Atlassian · Jira