CVE-2012-1500: XSS
Published Feb 13, 2020
·Updated
Stored XSS vulnerability in UpdateFieldJson.jspa in JIRA 4.4.3 and GreenHopper before 5.9.8 allows an attacker to inject arbitrary script code.
Affected Software
2 affected components
Atlassian Greenhopper<5.9.8
Atlassian Jira=4.4.3
Event History
Feb 13, 2020
CVE Published
via MITRE·04:02 PM
Data Sourced
via MITRE·04:02 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-1500?
CVE-2012-1500 is classified as a medium severity vulnerability due to the potential for stored XSS attacks.
2
How do I fix CVE-2012-1500?
To fix CVE-2012-1500, upgrade JIRA to version 4.4.4 or later, and GreenHopper to version 5.9.8 or later.
3
What types of systems are affected by CVE-2012-1500?
CVE-2012-1500 affects Atlassian JIRA version 4.4.3 and Atlassian GreenHopper versions prior to 5.9.8.
4
What impact does CVE-2012-1500 have on users?
CVE-2012-1500 allows attackers to inject arbitrary script code, compromising user data and session information.
5
Is CVE-2012-1500 a widely exploited vulnerability?
While not the most widely exploited vulnerability, CVE-2012-1500 poses a significant risk due to its nature and potential impact.