CVE Published: 19/02/2018 |
CVE Updated: 17/09/2024 |
CVE Year: 2017 Source: atlassian |
Vendor: Atlassian |
Product: Fisheye and Crucible Status : PUBLISHED
CVE-2017-18093 Description
Various resources in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and before 4.5.0 allow remote attackers who have permission to add or modify a repository to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the location setting of a configured repository.