CVE-2020-14166
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 1.9%
from disclosure to weapon280 days
Published on NVDJul 1
1st PoC+280d
exploitation probability
1.9%top 22% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
The /servicedesk/customer/portals resource in Jira Service Desk Server and Data Center before version 4.10.0 allows remote attackers with project administrator privileges to inject arbitrary HTML or JavaScript names via an Cross Site Scripting (XSS) vulnerability by uploading a html file.
Affected products
Atlassian · Jira Service Desk Server and Data Centerpublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/49748unverifiedcve_referencepacketstormsecurity.com/files/162107/Atlassian-Jira-Service-Desk-4.9.1-Cross-Site-Scripting.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.