CVE Published: 01/07/2020 |
CVE Updated: 16/09/2024 |
CVE Year: 2020 Source: atlassian |
Vendor: Atlassian |
Product: Jira Service Desk Server and Data Center Status : PUBLISHED
CVE-2020-14166 Description
The /servicedesk/customer/portals resource in Jira Service Desk Server and Data Center before version 4.10.0 allows remote attackers with project administrator privileges to inject arbitrary HTML or JavaScript names via an Cross Site Scripting (XSS) vulnerability by uploading a html file.