CVE-2018-20824: vulnerability in Atlassian Jira
Published · Updated
30Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 38%
exploitation probability
38%top 1% of all CVEs
observed exploitation
nono source reports it
The WallboardServlet resource in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the cyclePeriod parameter.
Affected products
Atlassian · JiraRelated CVEs — Atlassian Jira
In the same product, most dangerous first.