CVE Published: 10/07/2018 |
CVE Updated: 17/09/2024 |
CVE Year: 2018 Source: atlassian |
Vendor: Atlassian |
Product: Fisheye and Crucible Status : PUBLISHED
CVE-2018-13388 Description
The review attachment resource in Atlassian Fisheye and Crucible before version 4.5.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in attached files.